Advertisement
Guest User

Untitled

a guest
Aug 23rd, 2016
30
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 439.45 KB | None | 0 0
  1. Log Name: System
  2. Source: Microsoft-Windows-WindowsUpdateClient
  3. Date: 8/23/2016 6:48:10 PM
  4. Event ID: 20
  5. Task Category: Windows Update Agent
  6. Level: Error
  7. Keywords: Failure,Installation
  8. User: SYSTEM
  9. Computer: DESKTOP-D07KK79
  10. Description:
  11. Installation Failure: Windows failed to install the following update with error 0x80070643: Definition Update for Windows Defender - KB2267602 (Definition 1.227.512.0).
  12. Event Xml:
  13. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  14. <System>
  15. <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />
  16. <EventID>20</EventID>
  17. <Version>1</Version>
  18. <Level>2</Level>
  19. <Task>1</Task>
  20. <Opcode>13</Opcode>
  21. <Keywords>0x8000000000000028</Keywords>
  22. <TimeCreated SystemTime="2016-08-24T01:48:10.700576600Z" />
  23. <EventRecordID>1114</EventRecordID>
  24. <Correlation />
  25. <Execution ProcessID="636" ThreadID="612" />
  26. <Channel>System</Channel>
  27. <Computer>DESKTOP-D07KK79</Computer>
  28. <Security UserID="S-1-5-18" />
  29. </System>
  30. <EventData>
  31. <Data Name="errorCode">0x80070643</Data>
  32. <Data Name="updateTitle">Definition Update for Windows Defender - KB2267602 (Definition 1.227.512.0)</Data>
  33. <Data Name="updateGuid">{C8D50CE7-66E2-4E38-AE89-16551E17C299}</Data>
  34. <Data Name="updateRevisionNumber">200</Data>
  35. <Data Name="serviceGuid">{9482F4B4-E343-43B6-B170-9A65BC822C77}</Data>
  36. </EventData>
  37. </Event>
  38.  
  39. Log Name: System
  40. Source: Microsoft-Windows-DistributedCOM
  41. Date: 8/23/2016 6:42:21 PM
  42. Event ID: 10016
  43. Task Category: None
  44. Level: Error
  45. Keywords: Classic
  46. User: SYSTEM
  47. Computer: DESKTOP-D07KK79
  48. Description:
  49. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  50. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  51. and APPID
  52. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  53. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  54. Event Xml:
  55. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  56. <System>
  57. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  58. <EventID Qualifiers="0">10016</EventID>
  59. <Version>0</Version>
  60. <Level>2</Level>
  61. <Task>0</Task>
  62. <Opcode>0</Opcode>
  63. <Keywords>0x8080000000000000</Keywords>
  64. <TimeCreated SystemTime="2016-08-24T01:42:21.428181100Z" />
  65. <EventRecordID>1111</EventRecordID>
  66. <Correlation />
  67. <Execution ProcessID="1020" ThreadID="1368" />
  68. <Channel>System</Channel>
  69. <Computer>DESKTOP-D07KK79</Computer>
  70. <Security UserID="S-1-5-18" />
  71. </System>
  72. <EventData>
  73. <Data Name="param1">application-specific</Data>
  74. <Data Name="param2">Local</Data>
  75. <Data Name="param3">Activation</Data>
  76. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  77. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  78. <Data Name="param6">NT AUTHORITY</Data>
  79. <Data Name="param7">SYSTEM</Data>
  80. <Data Name="param8">S-1-5-18</Data>
  81. <Data Name="param9">LocalHost (Using LRPC)</Data>
  82. <Data Name="param10">Unavailable</Data>
  83. <Data Name="param11">Unavailable</Data>
  84. </EventData>
  85. </Event>
  86.  
  87. Log Name: Application
  88. Source: Application Error
  89. Date: 8/23/2016 6:38:08 PM
  90. Event ID: 1000
  91. Task Category: (100)
  92. Level: Error
  93. Keywords: Classic
  94. User: N/A
  95. Computer: DESKTOP-D07KK79
  96. Description:
  97. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  98. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  99. Exception code: 0xc0000409
  100. Fault offset: 0x000d96c2
  101. Faulting process id: 0xb3c
  102. Faulting application start time: 0x01d1fda817946ccb
  103. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  104. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  105. Report Id: 3ff5c283-fee1-4ea2-8ab4-3ed3c1abfe05
  106. Faulting package full name:
  107. Faulting package-relative application ID:
  108. Event Xml:
  109. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  110. <System>
  111. <Provider Name="Application Error" />
  112. <EventID Qualifiers="0">1000</EventID>
  113. <Level>2</Level>
  114. <Task>100</Task>
  115. <Keywords>0x80000000000000</Keywords>
  116. <TimeCreated SystemTime="2016-08-24T01:38:08.968965500Z" />
  117. <EventRecordID>702</EventRecordID>
  118. <Channel>Application</Channel>
  119. <Computer>DESKTOP-D07KK79</Computer>
  120. <Security />
  121. </System>
  122. <EventData>
  123. <Data>DipAwayMode.exe</Data>
  124. <Data>0.0.0.0</Data>
  125. <Data>00000000</Data>
  126. <Data>KERNELBASE.dll</Data>
  127. <Data>10.0.14393.0</Data>
  128. <Data>57898e34</Data>
  129. <Data>c0000409</Data>
  130. <Data>000d96c2</Data>
  131. <Data>b3c</Data>
  132. <Data>01d1fda817946ccb</Data>
  133. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  134. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  135. <Data>3ff5c283-fee1-4ea2-8ab4-3ed3c1abfe05</Data>
  136. <Data>
  137. </Data>
  138. <Data>
  139. </Data>
  140. </EventData>
  141. </Event>
  142.  
  143. Log Name: System
  144. Source: Microsoft-Windows-WER-SystemErrorReporting
  145. Date: 8/23/2016 6:37:43 PM
  146. Event ID: 1001
  147. Task Category: None
  148. Level: Error
  149. Keywords: Classic
  150. User: N/A
  151. Computer: DESKTOP-D07KK79
  152. Description:
  153. The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff800f2447e028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: f65d9ee7-dc42-411e-8478-c66a72ae4624.
  154. Event Xml:
  155. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  156. <System>
  157. <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
  158. <EventID Qualifiers="16384">1001</EventID>
  159. <Version>0</Version>
  160. <Level>2</Level>
  161. <Task>0</Task>
  162. <Opcode>0</Opcode>
  163. <Keywords>0x80000000000000</Keywords>
  164. <TimeCreated SystemTime="2016-08-24T01:37:43.538720700Z" />
  165. <EventRecordID>1109</EventRecordID>
  166. <Correlation />
  167. <Execution ProcessID="0" ThreadID="0" />
  168. <Channel>System</Channel>
  169. <Computer>DESKTOP-D07KK79</Computer>
  170. <Security />
  171. </System>
  172. <EventData>
  173. <Data Name="param1">0x00000124 (0x0000000000000000, 0xffff800f2447e028, 0x00000000be000000, 0x0000000000800400)</Data>
  174. <Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
  175. <Data Name="param3">f65d9ee7-dc42-411e-8478-c66a72ae4624</Data>
  176. </EventData>
  177. </Event>
  178.  
  179. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  180. Source: Microsoft-Windows-DeviceSetupManager
  181. Date: 8/23/2016 6:37:33 PM
  182. Event ID: 201
  183. Task Category: None
  184. Level: Warning
  185. Keywords:
  186. User: SYSTEM
  187. Computer: DESKTOP-D07KK79
  188. Description:
  189. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  190. Event Xml:
  191. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  192. <System>
  193. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  194. <EventID>201</EventID>
  195. <Version>0</Version>
  196. <Level>3</Level>
  197. <Task>0</Task>
  198. <Opcode>0</Opcode>
  199. <Keywords>0x4000000000000000</Keywords>
  200. <TimeCreated SystemTime="2016-08-24T01:37:33.410490300Z" />
  201. <EventRecordID>249</EventRecordID>
  202. <Correlation />
  203. <Execution ProcessID="636" ThreadID="1904" />
  204. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  205. <Computer>DESKTOP-D07KK79</Computer>
  206. <Security UserID="S-1-5-18" />
  207. </System>
  208. <EventData>
  209. </EventData>
  210. </Event>
  211.  
  212. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  213. Source: Microsoft-Windows-DeviceSetupManager
  214. Date: 8/23/2016 6:37:33 PM
  215. Event ID: 202
  216. Task Category: None
  217. Level: Warning
  218. Keywords:
  219. User: SYSTEM
  220. Computer: DESKTOP-D07KK79
  221. Description:
  222. The Network List Manager reports no connectivity to the internet.
  223. Event Xml:
  224. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  225. <System>
  226. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  227. <EventID>202</EventID>
  228. <Version>0</Version>
  229. <Level>3</Level>
  230. <Task>0</Task>
  231. <Opcode>0</Opcode>
  232. <Keywords>0x4000000000000000</Keywords>
  233. <TimeCreated SystemTime="2016-08-24T01:37:33.410410500Z" />
  234. <EventRecordID>248</EventRecordID>
  235. <Correlation />
  236. <Execution ProcessID="636" ThreadID="1904" />
  237. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  238. <Computer>DESKTOP-D07KK79</Computer>
  239. <Security UserID="S-1-5-18" />
  240. </System>
  241. <EventData>
  242. </EventData>
  243. </Event>
  244.  
  245. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  246. Source: Microsoft-Windows-DeviceSetupManager
  247. Date: 8/23/2016 6:37:33 PM
  248. Event ID: 201
  249. Task Category: None
  250. Level: Warning
  251. Keywords:
  252. User: SYSTEM
  253. Computer: DESKTOP-D07KK79
  254. Description:
  255. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  256. Event Xml:
  257. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  258. <System>
  259. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  260. <EventID>201</EventID>
  261. <Version>0</Version>
  262. <Level>3</Level>
  263. <Task>0</Task>
  264. <Opcode>0</Opcode>
  265. <Keywords>0x4000000000000000</Keywords>
  266. <TimeCreated SystemTime="2016-08-24T01:37:33.410263100Z" />
  267. <EventRecordID>247</EventRecordID>
  268. <Correlation />
  269. <Execution ProcessID="636" ThreadID="1896" />
  270. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  271. <Computer>DESKTOP-D07KK79</Computer>
  272. <Security UserID="S-1-5-18" />
  273. </System>
  274. <EventData>
  275. </EventData>
  276. </Event>
  277.  
  278. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  279. Source: Microsoft-Windows-DeviceSetupManager
  280. Date: 8/23/2016 6:37:33 PM
  281. Event ID: 202
  282. Task Category: None
  283. Level: Warning
  284. Keywords:
  285. User: SYSTEM
  286. Computer: DESKTOP-D07KK79
  287. Description:
  288. The Network List Manager reports no connectivity to the internet.
  289. Event Xml:
  290. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  291. <System>
  292. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  293. <EventID>202</EventID>
  294. <Version>0</Version>
  295. <Level>3</Level>
  296. <Task>0</Task>
  297. <Opcode>0</Opcode>
  298. <Keywords>0x4000000000000000</Keywords>
  299. <TimeCreated SystemTime="2016-08-24T01:37:33.410190400Z" />
  300. <EventRecordID>246</EventRecordID>
  301. <Correlation />
  302. <Execution ProcessID="636" ThreadID="1896" />
  303. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  304. <Computer>DESKTOP-D07KK79</Computer>
  305. <Security UserID="S-1-5-18" />
  306. </System>
  307. <EventData>
  308. </EventData>
  309. </Event>
  310.  
  311. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  312. Source: Microsoft-Windows-DeviceSetupManager
  313. Date: 8/23/2016 6:37:33 PM
  314. Event ID: 200
  315. Task Category: None
  316. Level: Warning
  317. Keywords:
  318. User: SYSTEM
  319. Computer: DESKTOP-D07KK79
  320. Description:
  321. A connection to the Windows Update service could not be established.
  322. Event Xml:
  323. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  324. <System>
  325. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  326. <EventID>200</EventID>
  327. <Version>0</Version>
  328. <Level>3</Level>
  329. <Task>0</Task>
  330. <Opcode>0</Opcode>
  331. <Keywords>0x4000000000000000</Keywords>
  332. <TimeCreated SystemTime="2016-08-24T01:37:33.270724800Z" />
  333. <EventRecordID>245</EventRecordID>
  334. <Correlation />
  335. <Execution ProcessID="636" ThreadID="1896" />
  336. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  337. <Computer>DESKTOP-D07KK79</Computer>
  338. <Security UserID="S-1-5-18" />
  339. </System>
  340. <EventData>
  341. </EventData>
  342. </Event>
  343.  
  344. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  345. Source: Microsoft-Windows-DeviceSetupManager
  346. Date: 8/23/2016 6:37:33 PM
  347. Event ID: 202
  348. Task Category: None
  349. Level: Warning
  350. Keywords:
  351. User: SYSTEM
  352. Computer: DESKTOP-D07KK79
  353. Description:
  354. The Network List Manager reports no connectivity to the internet.
  355. Event Xml:
  356. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  357. <System>
  358. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  359. <EventID>202</EventID>
  360. <Version>0</Version>
  361. <Level>3</Level>
  362. <Task>0</Task>
  363. <Opcode>0</Opcode>
  364. <Keywords>0x4000000000000000</Keywords>
  365. <TimeCreated SystemTime="2016-08-24T01:37:33.270630400Z" />
  366. <EventRecordID>244</EventRecordID>
  367. <Correlation />
  368. <Execution ProcessID="636" ThreadID="1896" />
  369. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  370. <Computer>DESKTOP-D07KK79</Computer>
  371. <Security UserID="S-1-5-18" />
  372. </System>
  373. <EventData>
  374. </EventData>
  375. </Event>
  376.  
  377. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  378. Source: Microsoft-Windows-DeviceSetupManager
  379. Date: 8/23/2016 6:37:33 PM
  380. Event ID: 200
  381. Task Category: None
  382. Level: Warning
  383. Keywords:
  384. User: SYSTEM
  385. Computer: DESKTOP-D07KK79
  386. Description:
  387. A connection to the Windows Update service could not be established.
  388. Event Xml:
  389. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  390. <System>
  391. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  392. <EventID>200</EventID>
  393. <Version>0</Version>
  394. <Level>3</Level>
  395. <Task>0</Task>
  396. <Opcode>0</Opcode>
  397. <Keywords>0x4000000000000000</Keywords>
  398. <TimeCreated SystemTime="2016-08-24T01:37:33.270439300Z" />
  399. <EventRecordID>243</EventRecordID>
  400. <Correlation />
  401. <Execution ProcessID="636" ThreadID="1888" />
  402. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  403. <Computer>DESKTOP-D07KK79</Computer>
  404. <Security UserID="S-1-5-18" />
  405. </System>
  406. <EventData>
  407. </EventData>
  408. </Event>
  409.  
  410. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  411. Source: Microsoft-Windows-DeviceSetupManager
  412. Date: 8/23/2016 6:37:33 PM
  413. Event ID: 202
  414. Task Category: None
  415. Level: Warning
  416. Keywords:
  417. User: SYSTEM
  418. Computer: DESKTOP-D07KK79
  419. Description:
  420. The Network List Manager reports no connectivity to the internet.
  421. Event Xml:
  422. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  423. <System>
  424. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  425. <EventID>202</EventID>
  426. <Version>0</Version>
  427. <Level>3</Level>
  428. <Task>0</Task>
  429. <Opcode>0</Opcode>
  430. <Keywords>0x4000000000000000</Keywords>
  431. <TimeCreated SystemTime="2016-08-24T01:37:33.270338500Z" />
  432. <EventRecordID>242</EventRecordID>
  433. <Correlation />
  434. <Execution ProcessID="636" ThreadID="1888" />
  435. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  436. <Computer>DESKTOP-D07KK79</Computer>
  437. <Security UserID="S-1-5-18" />
  438. </System>
  439. <EventData>
  440. </EventData>
  441. </Event>
  442.  
  443. Log Name: System
  444. Source: Microsoft-Windows-Kernel-PnP
  445. Date: 8/23/2016 6:37:17 PM
  446. Event ID: 219
  447. Task Category: (212)
  448. Level: Warning
  449. Keywords:
  450. User: SYSTEM
  451. Computer: DESKTOP-D07KK79
  452. Description:
  453. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  454. Event Xml:
  455. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  456. <System>
  457. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  458. <EventID>219</EventID>
  459. <Version>0</Version>
  460. <Level>3</Level>
  461. <Task>212</Task>
  462. <Opcode>0</Opcode>
  463. <Keywords>0x8000000000000000</Keywords>
  464. <TimeCreated SystemTime="2016-08-24T01:37:17.009384900Z" />
  465. <EventRecordID>1084</EventRecordID>
  466. <Correlation />
  467. <Execution ProcessID="4" ThreadID="400" />
  468. <Channel>System</Channel>
  469. <Computer>DESKTOP-D07KK79</Computer>
  470. <Security UserID="S-1-5-18" />
  471. </System>
  472. <EventData>
  473. <Data Name="DriverNameLength">24</Data>
  474. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  475. <Data Name="Status">3221226341</Data>
  476. <Data Name="FailureNameLength">14</Data>
  477. <Data Name="FailureName">\Driver\WUDFRd</Data>
  478. <Data Name="Version">0</Data>
  479. </EventData>
  480. </Event>
  481.  
  482. Log Name: Security
  483. Source: Microsoft-Windows-Eventlog
  484. Date: 8/23/2016 6:37:33 PM
  485. Event ID: 1101
  486. Task Category: Event processing
  487. Level: Error
  488. Keywords: Audit Success
  489. User: N/A
  490. Computer: DESKTOP-D07KK79
  491. Description:
  492. Audit events have been dropped by the transport. 0
  493. Event Xml:
  494. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  495. <System>
  496. <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
  497. <EventID>1101</EventID>
  498. <Version>0</Version>
  499. <Level>2</Level>
  500. <Task>101</Task>
  501. <Opcode>0</Opcode>
  502. <Keywords>0x4020000000000000</Keywords>
  503. <TimeCreated SystemTime="2016-08-24T01:37:33.812862300Z" />
  504. <EventRecordID>1402</EventRecordID>
  505. <Correlation />
  506. <Execution ProcessID="1560" ThreadID="2208" />
  507. <Channel>Security</Channel>
  508. <Computer>DESKTOP-D07KK79</Computer>
  509. <Security />
  510. </System>
  511. <UserData>
  512. <AuditEventsDropped xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
  513. <Reason>0</Reason>
  514. </AuditEventsDropped>
  515. </UserData>
  516. </Event>
  517.  
  518. Log Name: System
  519. Source: Microsoft-Windows-Kernel-Power
  520. Date: 8/23/2016 6:37:16 PM
  521. Event ID: 41
  522. Task Category: (63)
  523. Level: Critical
  524. Keywords: (70368744177664),(2)
  525. User: SYSTEM
  526. Computer: DESKTOP-D07KK79
  527. Description:
  528. The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
  529. Event Xml:
  530. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  531. <System>
  532. <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
  533. <EventID>41</EventID>
  534. <Version>4</Version>
  535. <Level>1</Level>
  536. <Task>63</Task>
  537. <Opcode>0</Opcode>
  538. <Keywords>0x8000400000000002</Keywords>
  539. <TimeCreated SystemTime="2016-08-24T01:37:16.821498700Z" />
  540. <EventRecordID>1081</EventRecordID>
  541. <Correlation />
  542. <Execution ProcessID="4" ThreadID="8" />
  543. <Channel>System</Channel>
  544. <Computer>DESKTOP-D07KK79</Computer>
  545. <Security UserID="S-1-5-18" />
  546. </System>
  547. <EventData>
  548. <Data Name="BugcheckCode">292</Data>
  549. <Data Name="BugcheckParameter1">0x0</Data>
  550. <Data Name="BugcheckParameter2">0xffff800f2447e028</Data>
  551. <Data Name="BugcheckParameter3">0xbe000000</Data>
  552. <Data Name="BugcheckParameter4">0x800400</Data>
  553. <Data Name="SleepInProgress">0</Data>
  554. <Data Name="PowerButtonTimestamp">0</Data>
  555. <Data Name="BootAppStatus">0</Data>
  556. <Data Name="Checkpoint">0</Data>
  557. <Data Name="ConnectedStandbyInProgress">false</Data>
  558. <Data Name="SystemSleepTransitionsToOn">0</Data>
  559. <Data Name="CsEntryScenarioInstanceId">0</Data>
  560. </EventData>
  561. </Event>
  562.  
  563. Log Name: System
  564. Source: EventLog
  565. Date: 8/23/2016 6:37:33 PM
  566. Event ID: 6008
  567. Task Category: None
  568. Level: Error
  569. Keywords: Classic
  570. User: N/A
  571. Computer: DESKTOP-D07KK79
  572. Description:
  573. The previous system shutdown at 6:30:39 PM on ‎8/‎23/‎2016 was unexpected.
  574. Event Xml:
  575. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  576. <System>
  577. <Provider Name="EventLog" />
  578. <EventID Qualifiers="32768">6008</EventID>
  579. <Level>2</Level>
  580. <Task>0</Task>
  581. <Keywords>0x80000000000000</Keywords>
  582. <TimeCreated SystemTime="2016-08-24T01:37:33.218810600Z" />
  583. <EventRecordID>1071</EventRecordID>
  584. <Channel>System</Channel>
  585. <Computer>DESKTOP-D07KK79</Computer>
  586. <Security />
  587. </System>
  588. <EventData>
  589. <Data>6:30:39 PM</Data>
  590. <Data>‎8/‎23/‎2016</Data>
  591. <Data>
  592. </Data>
  593. <Data>
  594. </Data>
  595. <Data>20</Data>
  596. <Data>
  597. </Data>
  598. <Data>
  599. </Data>
  600. <Binary>E00708000200170012001E0027006F01E00708000300180001001E0027006F013C0000003C000000010000003C00000000000000B00400000100000000000000</Binary>
  601. </EventData>
  602. </Event>
  603.  
  604. Log Name: Application
  605. Source: Application Error
  606. Date: 8/23/2016 6:31:43 PM
  607. Event ID: 1000
  608. Task Category: (100)
  609. Level: Error
  610. Keywords: Classic
  611. User: N/A
  612. Computer: DESKTOP-D07KK79
  613. Description:
  614. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  615. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  616. Exception code: 0xc0000409
  617. Fault offset: 0x000d96c2
  618. Faulting process id: 0xf20
  619. Faulting application start time: 0x01d1fda721d7bea5
  620. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  621. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  622. Report Id: a5ffa7e2-c083-49f0-b081-4d5aa6219394
  623. Faulting package full name:
  624. Faulting package-relative application ID:
  625. Event Xml:
  626. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  627. <System>
  628. <Provider Name="Application Error" />
  629. <EventID Qualifiers="0">1000</EventID>
  630. <Level>2</Level>
  631. <Task>100</Task>
  632. <Keywords>0x80000000000000</Keywords>
  633. <TimeCreated SystemTime="2016-08-24T01:31:43.733400300Z" />
  634. <EventRecordID>668</EventRecordID>
  635. <Channel>Application</Channel>
  636. <Computer>DESKTOP-D07KK79</Computer>
  637. <Security />
  638. </System>
  639. <EventData>
  640. <Data>DipAwayMode.exe</Data>
  641. <Data>0.0.0.0</Data>
  642. <Data>00000000</Data>
  643. <Data>KERNELBASE.dll</Data>
  644. <Data>10.0.14393.0</Data>
  645. <Data>57898e34</Data>
  646. <Data>c0000409</Data>
  647. <Data>000d96c2</Data>
  648. <Data>f20</Data>
  649. <Data>01d1fda721d7bea5</Data>
  650. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  651. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  652. <Data>a5ffa7e2-c083-49f0-b081-4d5aa6219394</Data>
  653. <Data>
  654. </Data>
  655. <Data>
  656. </Data>
  657. </EventData>
  658. </Event>
  659.  
  660. Log Name: System
  661. Source: Microsoft-Windows-WER-SystemErrorReporting
  662. Date: 8/23/2016 6:31:05 PM
  663. Event ID: 1001
  664. Task Category: None
  665. Level: Error
  666. Keywords: Classic
  667. User: N/A
  668. Computer: DESKTOP-D07KK79
  669. Description:
  670. The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe68e8ba78028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: e2ab756d-af6a-494a-a618-c7134468cc5a.
  671. Event Xml:
  672. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  673. <System>
  674. <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
  675. <EventID Qualifiers="16384">1001</EventID>
  676. <Version>0</Version>
  677. <Level>2</Level>
  678. <Task>0</Task>
  679. <Opcode>0</Opcode>
  680. <Keywords>0x80000000000000</Keywords>
  681. <TimeCreated SystemTime="2016-08-24T01:31:05.881432000Z" />
  682. <EventRecordID>1062</EventRecordID>
  683. <Correlation />
  684. <Execution ProcessID="0" ThreadID="0" />
  685. <Channel>System</Channel>
  686. <Computer>DESKTOP-D07KK79</Computer>
  687. <Security />
  688. </System>
  689. <EventData>
  690. <Data Name="param1">0x00000124 (0x0000000000000000, 0xffffe68e8ba78028, 0x00000000be000000, 0x0000000000800400)</Data>
  691. <Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
  692. <Data Name="param3">e2ab756d-af6a-494a-a618-c7134468cc5a</Data>
  693. </EventData>
  694. </Event>
  695.  
  696. Log Name: System
  697. Source: Microsoft-Windows-DistributedCOM
  698. Date: 8/23/2016 6:30:43 PM
  699. Event ID: 10016
  700. Task Category: None
  701. Level: Error
  702. Keywords: Classic
  703. User: SYSTEM
  704. Computer: DESKTOP-D07KK79
  705. Description:
  706. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  707. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  708. and APPID
  709. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  710. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  711. Event Xml:
  712. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  713. <System>
  714. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  715. <EventID Qualifiers="0">10016</EventID>
  716. <Version>0</Version>
  717. <Level>2</Level>
  718. <Task>0</Task>
  719. <Opcode>0</Opcode>
  720. <Keywords>0x8080000000000000</Keywords>
  721. <TimeCreated SystemTime="2016-08-24T01:30:43.963497400Z" />
  722. <EventRecordID>1061</EventRecordID>
  723. <Correlation />
  724. <Execution ProcessID="112" ThreadID="412" />
  725. <Channel>System</Channel>
  726. <Computer>DESKTOP-D07KK79</Computer>
  727. <Security UserID="S-1-5-18" />
  728. </System>
  729. <EventData>
  730. <Data Name="param1">application-specific</Data>
  731. <Data Name="param2">Local</Data>
  732. <Data Name="param3">Activation</Data>
  733. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  734. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  735. <Data Name="param6">NT AUTHORITY</Data>
  736. <Data Name="param7">SYSTEM</Data>
  737. <Data Name="param8">S-1-5-18</Data>
  738. <Data Name="param9">LocalHost (Using LRPC)</Data>
  739. <Data Name="param10">Unavailable</Data>
  740. <Data Name="param11">Unavailable</Data>
  741. </EventData>
  742. </Event>
  743.  
  744. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  745. Source: Microsoft-Windows-DeviceSetupManager
  746. Date: 8/23/2016 6:30:39 PM
  747. Event ID: 201
  748. Task Category: None
  749. Level: Warning
  750. Keywords:
  751. User: SYSTEM
  752. Computer: DESKTOP-D07KK79
  753. Description:
  754. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  755. Event Xml:
  756. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  757. <System>
  758. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  759. <EventID>201</EventID>
  760. <Version>0</Version>
  761. <Level>3</Level>
  762. <Task>0</Task>
  763. <Opcode>0</Opcode>
  764. <Keywords>0x4000000000000000</Keywords>
  765. <TimeCreated SystemTime="2016-08-24T01:30:39.907612600Z" />
  766. <EventRecordID>233</EventRecordID>
  767. <Correlation />
  768. <Execution ProcessID="548" ThreadID="1792" />
  769. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  770. <Computer>DESKTOP-D07KK79</Computer>
  771. <Security UserID="S-1-5-18" />
  772. </System>
  773. <EventData>
  774. </EventData>
  775. </Event>
  776.  
  777. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  778. Source: Microsoft-Windows-DeviceSetupManager
  779. Date: 8/23/2016 6:30:39 PM
  780. Event ID: 202
  781. Task Category: None
  782. Level: Warning
  783. Keywords:
  784. User: SYSTEM
  785. Computer: DESKTOP-D07KK79
  786. Description:
  787. The Network List Manager reports no connectivity to the internet.
  788. Event Xml:
  789. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  790. <System>
  791. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  792. <EventID>202</EventID>
  793. <Version>0</Version>
  794. <Level>3</Level>
  795. <Task>0</Task>
  796. <Opcode>0</Opcode>
  797. <Keywords>0x4000000000000000</Keywords>
  798. <TimeCreated SystemTime="2016-08-24T01:30:39.907537200Z" />
  799. <EventRecordID>232</EventRecordID>
  800. <Correlation />
  801. <Execution ProcessID="548" ThreadID="1792" />
  802. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  803. <Computer>DESKTOP-D07KK79</Computer>
  804. <Security UserID="S-1-5-18" />
  805. </System>
  806. <EventData>
  807. </EventData>
  808. </Event>
  809.  
  810. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  811. Source: Microsoft-Windows-DeviceSetupManager
  812. Date: 8/23/2016 6:30:39 PM
  813. Event ID: 201
  814. Task Category: None
  815. Level: Warning
  816. Keywords:
  817. User: SYSTEM
  818. Computer: DESKTOP-D07KK79
  819. Description:
  820. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  821. Event Xml:
  822. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  823. <System>
  824. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  825. <EventID>201</EventID>
  826. <Version>0</Version>
  827. <Level>3</Level>
  828. <Task>0</Task>
  829. <Opcode>0</Opcode>
  830. <Keywords>0x4000000000000000</Keywords>
  831. <TimeCreated SystemTime="2016-08-24T01:30:39.907434800Z" />
  832. <EventRecordID>231</EventRecordID>
  833. <Correlation />
  834. <Execution ProcessID="548" ThreadID="1744" />
  835. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  836. <Computer>DESKTOP-D07KK79</Computer>
  837. <Security UserID="S-1-5-18" />
  838. </System>
  839. <EventData>
  840. </EventData>
  841. </Event>
  842.  
  843. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  844. Source: Microsoft-Windows-DeviceSetupManager
  845. Date: 8/23/2016 6:30:39 PM
  846. Event ID: 202
  847. Task Category: None
  848. Level: Warning
  849. Keywords:
  850. User: SYSTEM
  851. Computer: DESKTOP-D07KK79
  852. Description:
  853. The Network List Manager reports no connectivity to the internet.
  854. Event Xml:
  855. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  856. <System>
  857. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  858. <EventID>202</EventID>
  859. <Version>0</Version>
  860. <Level>3</Level>
  861. <Task>0</Task>
  862. <Opcode>0</Opcode>
  863. <Keywords>0x4000000000000000</Keywords>
  864. <TimeCreated SystemTime="2016-08-24T01:30:39.907354000Z" />
  865. <EventRecordID>230</EventRecordID>
  866. <Correlation />
  867. <Execution ProcessID="548" ThreadID="1744" />
  868. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  869. <Computer>DESKTOP-D07KK79</Computer>
  870. <Security UserID="S-1-5-18" />
  871. </System>
  872. <EventData>
  873. </EventData>
  874. </Event>
  875.  
  876. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  877. Source: Microsoft-Windows-DeviceSetupManager
  878. Date: 8/23/2016 6:30:39 PM
  879. Event ID: 200
  880. Task Category: None
  881. Level: Warning
  882. Keywords:
  883. User: SYSTEM
  884. Computer: DESKTOP-D07KK79
  885. Description:
  886. A connection to the Windows Update service could not be established.
  887. Event Xml:
  888. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  889. <System>
  890. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  891. <EventID>200</EventID>
  892. <Version>0</Version>
  893. <Level>3</Level>
  894. <Task>0</Task>
  895. <Opcode>0</Opcode>
  896. <Keywords>0x4000000000000000</Keywords>
  897. <TimeCreated SystemTime="2016-08-24T01:30:39.421892200Z" />
  898. <EventRecordID>229</EventRecordID>
  899. <Correlation />
  900. <Execution ProcessID="548" ThreadID="1792" />
  901. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  902. <Computer>DESKTOP-D07KK79</Computer>
  903. <Security UserID="S-1-5-18" />
  904. </System>
  905. <EventData>
  906. </EventData>
  907. </Event>
  908.  
  909. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  910. Source: Microsoft-Windows-DeviceSetupManager
  911. Date: 8/23/2016 6:30:39 PM
  912. Event ID: 202
  913. Task Category: None
  914. Level: Warning
  915. Keywords:
  916. User: SYSTEM
  917. Computer: DESKTOP-D07KK79
  918. Description:
  919. The Network List Manager reports no connectivity to the internet.
  920. Event Xml:
  921. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  922. <System>
  923. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  924. <EventID>202</EventID>
  925. <Version>0</Version>
  926. <Level>3</Level>
  927. <Task>0</Task>
  928. <Opcode>0</Opcode>
  929. <Keywords>0x4000000000000000</Keywords>
  930. <TimeCreated SystemTime="2016-08-24T01:30:39.421784300Z" />
  931. <EventRecordID>228</EventRecordID>
  932. <Correlation />
  933. <Execution ProcessID="548" ThreadID="1792" />
  934. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  935. <Computer>DESKTOP-D07KK79</Computer>
  936. <Security UserID="S-1-5-18" />
  937. </System>
  938. <EventData>
  939. </EventData>
  940. </Event>
  941.  
  942. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  943. Source: Microsoft-Windows-DeviceSetupManager
  944. Date: 8/23/2016 6:30:39 PM
  945. Event ID: 200
  946. Task Category: None
  947. Level: Warning
  948. Keywords:
  949. User: SYSTEM
  950. Computer: DESKTOP-D07KK79
  951. Description:
  952. A connection to the Windows Update service could not be established.
  953. Event Xml:
  954. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  955. <System>
  956. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  957. <EventID>200</EventID>
  958. <Version>0</Version>
  959. <Level>3</Level>
  960. <Task>0</Task>
  961. <Opcode>0</Opcode>
  962. <Keywords>0x4000000000000000</Keywords>
  963. <TimeCreated SystemTime="2016-08-24T01:30:39.421439300Z" />
  964. <EventRecordID>227</EventRecordID>
  965. <Correlation />
  966. <Execution ProcessID="548" ThreadID="1788" />
  967. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  968. <Computer>DESKTOP-D07KK79</Computer>
  969. <Security UserID="S-1-5-18" />
  970. </System>
  971. <EventData>
  972. </EventData>
  973. </Event>
  974.  
  975. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  976. Source: Microsoft-Windows-DeviceSetupManager
  977. Date: 8/23/2016 6:30:39 PM
  978. Event ID: 202
  979. Task Category: None
  980. Level: Warning
  981. Keywords:
  982. User: SYSTEM
  983. Computer: DESKTOP-D07KK79
  984. Description:
  985. The Network List Manager reports no connectivity to the internet.
  986. Event Xml:
  987. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  988. <System>
  989. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  990. <EventID>202</EventID>
  991. <Version>0</Version>
  992. <Level>3</Level>
  993. <Task>0</Task>
  994. <Opcode>0</Opcode>
  995. <Keywords>0x4000000000000000</Keywords>
  996. <TimeCreated SystemTime="2016-08-24T01:30:39.421287700Z" />
  997. <EventRecordID>226</EventRecordID>
  998. <Correlation />
  999. <Execution ProcessID="548" ThreadID="1788" />
  1000. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1001. <Computer>DESKTOP-D07KK79</Computer>
  1002. <Security UserID="S-1-5-18" />
  1003. </System>
  1004. <EventData>
  1005. </EventData>
  1006. </Event>
  1007.  
  1008. Log Name: System
  1009. Source: Microsoft-Windows-Kernel-PnP
  1010. Date: 8/23/2016 6:30:27 PM
  1011. Event ID: 219
  1012. Task Category: (212)
  1013. Level: Warning
  1014. Keywords:
  1015. User: SYSTEM
  1016. Computer: DESKTOP-D07KK79
  1017. Description:
  1018. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  1019. Event Xml:
  1020. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1021. <System>
  1022. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  1023. <EventID>219</EventID>
  1024. <Version>0</Version>
  1025. <Level>3</Level>
  1026. <Task>212</Task>
  1027. <Opcode>0</Opcode>
  1028. <Keywords>0x8000000000000000</Keywords>
  1029. <TimeCreated SystemTime="2016-08-24T01:30:27.083774400Z" />
  1030. <EventRecordID>1036</EventRecordID>
  1031. <Correlation />
  1032. <Execution ProcessID="4" ThreadID="404" />
  1033. <Channel>System</Channel>
  1034. <Computer>DESKTOP-D07KK79</Computer>
  1035. <Security UserID="S-1-5-18" />
  1036. </System>
  1037. <EventData>
  1038. <Data Name="DriverNameLength">24</Data>
  1039. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  1040. <Data Name="Status">3221226341</Data>
  1041. <Data Name="FailureNameLength">14</Data>
  1042. <Data Name="FailureName">\Driver\WUDFRd</Data>
  1043. <Data Name="Version">0</Data>
  1044. </EventData>
  1045. </Event>
  1046.  
  1047. Log Name: Security
  1048. Source: Microsoft-Windows-Eventlog
  1049. Date: 8/23/2016 6:30:40 PM
  1050. Event ID: 1101
  1051. Task Category: Event processing
  1052. Level: Error
  1053. Keywords: Audit Success
  1054. User: N/A
  1055. Computer: DESKTOP-D07KK79
  1056. Description:
  1057. Audit events have been dropped by the transport. 0
  1058. Event Xml:
  1059. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1060. <System>
  1061. <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
  1062. <EventID>1101</EventID>
  1063. <Version>0</Version>
  1064. <Level>2</Level>
  1065. <Task>101</Task>
  1066. <Opcode>0</Opcode>
  1067. <Keywords>0x4020000000000000</Keywords>
  1068. <TimeCreated SystemTime="2016-08-24T01:30:40.189164000Z" />
  1069. <EventRecordID>1328</EventRecordID>
  1070. <Correlation />
  1071. <Execution ProcessID="1536" ThreadID="2264" />
  1072. <Channel>Security</Channel>
  1073. <Computer>DESKTOP-D07KK79</Computer>
  1074. <Security />
  1075. </System>
  1076. <UserData>
  1077. <AuditEventsDropped xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
  1078. <Reason>0</Reason>
  1079. </AuditEventsDropped>
  1080. </UserData>
  1081. </Event>
  1082.  
  1083. Log Name: System
  1084. Source: Microsoft-Windows-Kernel-Power
  1085. Date: 8/23/2016 6:30:22 PM
  1086. Event ID: 41
  1087. Task Category: (63)
  1088. Level: Critical
  1089. Keywords: (70368744177664),(2)
  1090. User: SYSTEM
  1091. Computer: DESKTOP-D07KK79
  1092. Description:
  1093. The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
  1094. Event Xml:
  1095. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1096. <System>
  1097. <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
  1098. <EventID>41</EventID>
  1099. <Version>4</Version>
  1100. <Level>1</Level>
  1101. <Task>63</Task>
  1102. <Opcode>0</Opcode>
  1103. <Keywords>0x8000400000000002</Keywords>
  1104. <TimeCreated SystemTime="2016-08-24T01:30:22.897231700Z" />
  1105. <EventRecordID>1033</EventRecordID>
  1106. <Correlation />
  1107. <Execution ProcessID="4" ThreadID="8" />
  1108. <Channel>System</Channel>
  1109. <Computer>DESKTOP-D07KK79</Computer>
  1110. <Security UserID="S-1-5-18" />
  1111. </System>
  1112. <EventData>
  1113. <Data Name="BugcheckCode">292</Data>
  1114. <Data Name="BugcheckParameter1">0x0</Data>
  1115. <Data Name="BugcheckParameter2">0xffffe68e8ba78028</Data>
  1116. <Data Name="BugcheckParameter3">0xbe000000</Data>
  1117. <Data Name="BugcheckParameter4">0x800400</Data>
  1118. <Data Name="SleepInProgress">0</Data>
  1119. <Data Name="PowerButtonTimestamp">0</Data>
  1120. <Data Name="BootAppStatus">0</Data>
  1121. <Data Name="Checkpoint">0</Data>
  1122. <Data Name="ConnectedStandbyInProgress">false</Data>
  1123. <Data Name="SystemSleepTransitionsToOn">0</Data>
  1124. <Data Name="CsEntryScenarioInstanceId">0</Data>
  1125. </EventData>
  1126. </Event>
  1127.  
  1128. Log Name: System
  1129. Source: EventLog
  1130. Date: 8/23/2016 6:30:39 PM
  1131. Event ID: 6008
  1132. Task Category: None
  1133. Level: Error
  1134. Keywords: Classic
  1135. User: N/A
  1136. Computer: DESKTOP-D07KK79
  1137. Description:
  1138. The previous system shutdown at 6:23:19 PM on ‎8/‎23/‎2016 was unexpected.
  1139. Event Xml:
  1140. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1141. <System>
  1142. <Provider Name="EventLog" />
  1143. <EventID Qualifiers="32768">6008</EventID>
  1144. <Level>2</Level>
  1145. <Task>0</Task>
  1146. <Keywords>0x80000000000000</Keywords>
  1147. <TimeCreated SystemTime="2016-08-24T01:30:39.366091600Z" />
  1148. <EventRecordID>1016</EventRecordID>
  1149. <Channel>System</Channel>
  1150. <Computer>DESKTOP-D07KK79</Computer>
  1151. <Security />
  1152. </System>
  1153. <EventData>
  1154. <Data>6:23:19 PM</Data>
  1155. <Data>‎8/‎23/‎2016</Data>
  1156. <Data>
  1157. </Data>
  1158. <Data>
  1159. </Data>
  1160. <Data>28</Data>
  1161. <Data>
  1162. </Data>
  1163. <Data>
  1164. </Data>
  1165. <Binary>E0070800020017001200170013004103E00708000300180001001700130041033C0000003C000000010000003C00000000000000B00400000100000000000000</Binary>
  1166. </EventData>
  1167. </Event>
  1168.  
  1169. Log Name: Application
  1170. Source: Application Error
  1171. Date: 8/23/2016 6:23:52 PM
  1172. Event ID: 1000
  1173. Task Category: (100)
  1174. Level: Error
  1175. Keywords: Classic
  1176. User: N/A
  1177. Computer: DESKTOP-D07KK79
  1178. Description:
  1179. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  1180. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  1181. Exception code: 0xc0000409
  1182. Fault offset: 0x000d96c2
  1183. Faulting process id: 0x103c
  1184. Faulting application start time: 0x01d1fda621052178
  1185. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  1186. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  1187. Report Id: 39f9f7f5-3786-4b7a-a86b-05f1ff7ee55f
  1188. Faulting package full name:
  1189. Faulting package-relative application ID:
  1190. Event Xml:
  1191. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1192. <System>
  1193. <Provider Name="Application Error" />
  1194. <EventID Qualifiers="0">1000</EventID>
  1195. <Level>2</Level>
  1196. <Task>100</Task>
  1197. <Keywords>0x80000000000000</Keywords>
  1198. <TimeCreated SystemTime="2016-08-24T01:23:52.583250800Z" />
  1199. <EventRecordID>629</EventRecordID>
  1200. <Channel>Application</Channel>
  1201. <Computer>DESKTOP-D07KK79</Computer>
  1202. <Security />
  1203. </System>
  1204. <EventData>
  1205. <Data>DipAwayMode.exe</Data>
  1206. <Data>0.0.0.0</Data>
  1207. <Data>00000000</Data>
  1208. <Data>KERNELBASE.dll</Data>
  1209. <Data>10.0.14393.0</Data>
  1210. <Data>57898e34</Data>
  1211. <Data>c0000409</Data>
  1212. <Data>000d96c2</Data>
  1213. <Data>103c</Data>
  1214. <Data>01d1fda621052178</Data>
  1215. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  1216. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  1217. <Data>39f9f7f5-3786-4b7a-a86b-05f1ff7ee55f</Data>
  1218. <Data>
  1219. </Data>
  1220. <Data>
  1221. </Data>
  1222. </EventData>
  1223. </Event>
  1224.  
  1225. Log Name: System
  1226. Source: Microsoft-Windows-DistributedCOM
  1227. Date: 8/23/2016 6:23:33 PM
  1228. Event ID: 10016
  1229. Task Category: None
  1230. Level: Error
  1231. Keywords: Classic
  1232. User: SYSTEM
  1233. Computer: DESKTOP-D07KK79
  1234. Description:
  1235. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  1236. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  1237. and APPID
  1238. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  1239. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  1240. Event Xml:
  1241. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1242. <System>
  1243. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  1244. <EventID Qualifiers="0">10016</EventID>
  1245. <Version>0</Version>
  1246. <Level>2</Level>
  1247. <Task>0</Task>
  1248. <Opcode>0</Opcode>
  1249. <Keywords>0x8080000000000000</Keywords>
  1250. <TimeCreated SystemTime="2016-08-24T01:23:33.099531300Z" />
  1251. <EventRecordID>1013</EventRecordID>
  1252. <Correlation />
  1253. <Execution ProcessID="992" ThreadID="2572" />
  1254. <Channel>System</Channel>
  1255. <Computer>DESKTOP-D07KK79</Computer>
  1256. <Security UserID="S-1-5-18" />
  1257. </System>
  1258. <EventData>
  1259. <Data Name="param1">application-specific</Data>
  1260. <Data Name="param2">Local</Data>
  1261. <Data Name="param3">Activation</Data>
  1262. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  1263. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  1264. <Data Name="param6">NT AUTHORITY</Data>
  1265. <Data Name="param7">SYSTEM</Data>
  1266. <Data Name="param8">S-1-5-18</Data>
  1267. <Data Name="param9">LocalHost (Using LRPC)</Data>
  1268. <Data Name="param10">Unavailable</Data>
  1269. <Data Name="param11">Unavailable</Data>
  1270. </EventData>
  1271. </Event>
  1272.  
  1273. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1274. Source: Microsoft-Windows-DeviceSetupManager
  1275. Date: 8/23/2016 6:23:20 PM
  1276. Event ID: 201
  1277. Task Category: None
  1278. Level: Warning
  1279. Keywords:
  1280. User: SYSTEM
  1281. Computer: DESKTOP-D07KK79
  1282. Description:
  1283. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  1284. Event Xml:
  1285. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1286. <System>
  1287. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1288. <EventID>201</EventID>
  1289. <Version>0</Version>
  1290. <Level>3</Level>
  1291. <Task>0</Task>
  1292. <Opcode>0</Opcode>
  1293. <Keywords>0x4000000000000000</Keywords>
  1294. <TimeCreated SystemTime="2016-08-24T01:23:20.231083700Z" />
  1295. <EventRecordID>217</EventRecordID>
  1296. <Correlation />
  1297. <Execution ProcessID="528" ThreadID="1916" />
  1298. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1299. <Computer>DESKTOP-D07KK79</Computer>
  1300. <Security UserID="S-1-5-18" />
  1301. </System>
  1302. <EventData>
  1303. </EventData>
  1304. </Event>
  1305.  
  1306. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1307. Source: Microsoft-Windows-DeviceSetupManager
  1308. Date: 8/23/2016 6:23:20 PM
  1309. Event ID: 202
  1310. Task Category: None
  1311. Level: Warning
  1312. Keywords:
  1313. User: SYSTEM
  1314. Computer: DESKTOP-D07KK79
  1315. Description:
  1316. The Network List Manager reports no connectivity to the internet.
  1317. Event Xml:
  1318. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1319. <System>
  1320. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1321. <EventID>202</EventID>
  1322. <Version>0</Version>
  1323. <Level>3</Level>
  1324. <Task>0</Task>
  1325. <Opcode>0</Opcode>
  1326. <Keywords>0x4000000000000000</Keywords>
  1327. <TimeCreated SystemTime="2016-08-24T01:23:20.231014600Z" />
  1328. <EventRecordID>216</EventRecordID>
  1329. <Correlation />
  1330. <Execution ProcessID="528" ThreadID="1916" />
  1331. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1332. <Computer>DESKTOP-D07KK79</Computer>
  1333. <Security UserID="S-1-5-18" />
  1334. </System>
  1335. <EventData>
  1336. </EventData>
  1337. </Event>
  1338.  
  1339. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1340. Source: Microsoft-Windows-DeviceSetupManager
  1341. Date: 8/23/2016 6:23:20 PM
  1342. Event ID: 201
  1343. Task Category: None
  1344. Level: Warning
  1345. Keywords:
  1346. User: SYSTEM
  1347. Computer: DESKTOP-D07KK79
  1348. Description:
  1349. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  1350. Event Xml:
  1351. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1352. <System>
  1353. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1354. <EventID>201</EventID>
  1355. <Version>0</Version>
  1356. <Level>3</Level>
  1357. <Task>0</Task>
  1358. <Opcode>0</Opcode>
  1359. <Keywords>0x4000000000000000</Keywords>
  1360. <TimeCreated SystemTime="2016-08-24T01:23:20.230890700Z" />
  1361. <EventRecordID>215</EventRecordID>
  1362. <Correlation />
  1363. <Execution ProcessID="528" ThreadID="1904" />
  1364. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1365. <Computer>DESKTOP-D07KK79</Computer>
  1366. <Security UserID="S-1-5-18" />
  1367. </System>
  1368. <EventData>
  1369. </EventData>
  1370. </Event>
  1371.  
  1372. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1373. Source: Microsoft-Windows-DeviceSetupManager
  1374. Date: 8/23/2016 6:23:20 PM
  1375. Event ID: 202
  1376. Task Category: None
  1377. Level: Warning
  1378. Keywords:
  1379. User: SYSTEM
  1380. Computer: DESKTOP-D07KK79
  1381. Description:
  1382. The Network List Manager reports no connectivity to the internet.
  1383. Event Xml:
  1384. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1385. <System>
  1386. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1387. <EventID>202</EventID>
  1388. <Version>0</Version>
  1389. <Level>3</Level>
  1390. <Task>0</Task>
  1391. <Opcode>0</Opcode>
  1392. <Keywords>0x4000000000000000</Keywords>
  1393. <TimeCreated SystemTime="2016-08-24T01:23:20.230822900Z" />
  1394. <EventRecordID>214</EventRecordID>
  1395. <Correlation />
  1396. <Execution ProcessID="528" ThreadID="1904" />
  1397. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1398. <Computer>DESKTOP-D07KK79</Computer>
  1399. <Security UserID="S-1-5-18" />
  1400. </System>
  1401. <EventData>
  1402. </EventData>
  1403. </Event>
  1404.  
  1405. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1406. Source: Microsoft-Windows-DeviceSetupManager
  1407. Date: 8/23/2016 6:23:19 PM
  1408. Event ID: 200
  1409. Task Category: None
  1410. Level: Warning
  1411. Keywords:
  1412. User: SYSTEM
  1413. Computer: DESKTOP-D07KK79
  1414. Description:
  1415. A connection to the Windows Update service could not be established.
  1416. Event Xml:
  1417. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1418. <System>
  1419. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1420. <EventID>200</EventID>
  1421. <Version>0</Version>
  1422. <Level>3</Level>
  1423. <Task>0</Task>
  1424. <Opcode>0</Opcode>
  1425. <Keywords>0x4000000000000000</Keywords>
  1426. <TimeCreated SystemTime="2016-08-24T01:23:19.878345200Z" />
  1427. <EventRecordID>213</EventRecordID>
  1428. <Correlation />
  1429. <Execution ProcessID="528" ThreadID="1916" />
  1430. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1431. <Computer>DESKTOP-D07KK79</Computer>
  1432. <Security UserID="S-1-5-18" />
  1433. </System>
  1434. <EventData>
  1435. </EventData>
  1436. </Event>
  1437.  
  1438. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1439. Source: Microsoft-Windows-DeviceSetupManager
  1440. Date: 8/23/2016 6:23:19 PM
  1441. Event ID: 202
  1442. Task Category: None
  1443. Level: Warning
  1444. Keywords:
  1445. User: SYSTEM
  1446. Computer: DESKTOP-D07KK79
  1447. Description:
  1448. The Network List Manager reports no connectivity to the internet.
  1449. Event Xml:
  1450. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1451. <System>
  1452. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1453. <EventID>202</EventID>
  1454. <Version>0</Version>
  1455. <Level>3</Level>
  1456. <Task>0</Task>
  1457. <Opcode>0</Opcode>
  1458. <Keywords>0x4000000000000000</Keywords>
  1459. <TimeCreated SystemTime="2016-08-24T01:23:19.878261400Z" />
  1460. <EventRecordID>212</EventRecordID>
  1461. <Correlation />
  1462. <Execution ProcessID="528" ThreadID="1916" />
  1463. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1464. <Computer>DESKTOP-D07KK79</Computer>
  1465. <Security UserID="S-1-5-18" />
  1466. </System>
  1467. <EventData>
  1468. </EventData>
  1469. </Event>
  1470.  
  1471. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1472. Source: Microsoft-Windows-DeviceSetupManager
  1473. Date: 8/23/2016 6:23:19 PM
  1474. Event ID: 200
  1475. Task Category: None
  1476. Level: Warning
  1477. Keywords:
  1478. User: SYSTEM
  1479. Computer: DESKTOP-D07KK79
  1480. Description:
  1481. A connection to the Windows Update service could not be established.
  1482. Event Xml:
  1483. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1484. <System>
  1485. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1486. <EventID>200</EventID>
  1487. <Version>0</Version>
  1488. <Level>3</Level>
  1489. <Task>0</Task>
  1490. <Opcode>0</Opcode>
  1491. <Keywords>0x4000000000000000</Keywords>
  1492. <TimeCreated SystemTime="2016-08-24T01:23:19.877541200Z" />
  1493. <EventRecordID>211</EventRecordID>
  1494. <Correlation />
  1495. <Execution ProcessID="528" ThreadID="1912" />
  1496. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1497. <Computer>DESKTOP-D07KK79</Computer>
  1498. <Security UserID="S-1-5-18" />
  1499. </System>
  1500. <EventData>
  1501. </EventData>
  1502. </Event>
  1503.  
  1504. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1505. Source: Microsoft-Windows-DeviceSetupManager
  1506. Date: 8/23/2016 6:23:19 PM
  1507. Event ID: 202
  1508. Task Category: None
  1509. Level: Warning
  1510. Keywords:
  1511. User: SYSTEM
  1512. Computer: DESKTOP-D07KK79
  1513. Description:
  1514. The Network List Manager reports no connectivity to the internet.
  1515. Event Xml:
  1516. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1517. <System>
  1518. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1519. <EventID>202</EventID>
  1520. <Version>0</Version>
  1521. <Level>3</Level>
  1522. <Task>0</Task>
  1523. <Opcode>0</Opcode>
  1524. <Keywords>0x4000000000000000</Keywords>
  1525. <TimeCreated SystemTime="2016-08-24T01:23:19.877437200Z" />
  1526. <EventRecordID>210</EventRecordID>
  1527. <Correlation />
  1528. <Execution ProcessID="528" ThreadID="1912" />
  1529. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1530. <Computer>DESKTOP-D07KK79</Computer>
  1531. <Security UserID="S-1-5-18" />
  1532. </System>
  1533. <EventData>
  1534. </EventData>
  1535. </Event>
  1536.  
  1537. Log Name: System
  1538. Source: Microsoft-Windows-Kernel-PnP
  1539. Date: 8/23/2016 6:23:03 PM
  1540. Event ID: 219
  1541. Task Category: (212)
  1542. Level: Warning
  1543. Keywords:
  1544. User: SYSTEM
  1545. Computer: DESKTOP-D07KK79
  1546. Description:
  1547. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  1548. Event Xml:
  1549. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1550. <System>
  1551. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  1552. <EventID>219</EventID>
  1553. <Version>0</Version>
  1554. <Level>3</Level>
  1555. <Task>212</Task>
  1556. <Opcode>0</Opcode>
  1557. <Keywords>0x8000000000000000</Keywords>
  1558. <TimeCreated SystemTime="2016-08-24T01:23:03.334946100Z" />
  1559. <EventRecordID>988</EventRecordID>
  1560. <Correlation />
  1561. <Execution ProcessID="4" ThreadID="420" />
  1562. <Channel>System</Channel>
  1563. <Computer>DESKTOP-D07KK79</Computer>
  1564. <Security UserID="S-1-5-18" />
  1565. </System>
  1566. <EventData>
  1567. <Data Name="DriverNameLength">24</Data>
  1568. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  1569. <Data Name="Status">3221226341</Data>
  1570. <Data Name="FailureNameLength">14</Data>
  1571. <Data Name="FailureName">\Driver\WUDFRd</Data>
  1572. <Data Name="Version">0</Data>
  1573. </EventData>
  1574. </Event>
  1575.  
  1576. Log Name: Security
  1577. Source: Microsoft-Windows-Eventlog
  1578. Date: 8/23/2016 6:23:20 PM
  1579. Event ID: 1101
  1580. Task Category: Event processing
  1581. Level: Error
  1582. Keywords: Audit Success
  1583. User: N/A
  1584. Computer: DESKTOP-D07KK79
  1585. Description:
  1586. Audit events have been dropped by the transport. 0
  1587. Event Xml:
  1588. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1589. <System>
  1590. <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
  1591. <EventID>1101</EventID>
  1592. <Version>0</Version>
  1593. <Level>2</Level>
  1594. <Task>101</Task>
  1595. <Opcode>0</Opcode>
  1596. <Keywords>0x4020000000000000</Keywords>
  1597. <TimeCreated SystemTime="2016-08-24T01:23:20.779443300Z" />
  1598. <EventRecordID>1251</EventRecordID>
  1599. <Correlation />
  1600. <Execution ProcessID="1488" ThreadID="1700" />
  1601. <Channel>Security</Channel>
  1602. <Computer>DESKTOP-D07KK79</Computer>
  1603. <Security />
  1604. </System>
  1605. <UserData>
  1606. <AuditEventsDropped xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
  1607. <Reason>0</Reason>
  1608. </AuditEventsDropped>
  1609. </UserData>
  1610. </Event>
  1611.  
  1612. Log Name: System
  1613. Source: Microsoft-Windows-Kernel-Power
  1614. Date: 8/23/2016 6:23:03 PM
  1615. Event ID: 41
  1616. Task Category: (63)
  1617. Level: Critical
  1618. Keywords: (70368744177664),(2)
  1619. User: SYSTEM
  1620. Computer: DESKTOP-D07KK79
  1621. Description:
  1622. The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
  1623. Event Xml:
  1624. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1625. <System>
  1626. <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
  1627. <EventID>41</EventID>
  1628. <Version>4</Version>
  1629. <Level>1</Level>
  1630. <Task>63</Task>
  1631. <Opcode>0</Opcode>
  1632. <Keywords>0x8000400000000002</Keywords>
  1633. <TimeCreated SystemTime="2016-08-24T01:23:03.155275400Z" />
  1634. <EventRecordID>985</EventRecordID>
  1635. <Correlation />
  1636. <Execution ProcessID="4" ThreadID="8" />
  1637. <Channel>System</Channel>
  1638. <Computer>DESKTOP-D07KK79</Computer>
  1639. <Security UserID="S-1-5-18" />
  1640. </System>
  1641. <EventData>
  1642. <Data Name="BugcheckCode">0</Data>
  1643. <Data Name="BugcheckParameter1">0x0</Data>
  1644. <Data Name="BugcheckParameter2">0x0</Data>
  1645. <Data Name="BugcheckParameter3">0x0</Data>
  1646. <Data Name="BugcheckParameter4">0x0</Data>
  1647. <Data Name="SleepInProgress">0</Data>
  1648. <Data Name="PowerButtonTimestamp">0</Data>
  1649. <Data Name="BootAppStatus">0</Data>
  1650. <Data Name="Checkpoint">0</Data>
  1651. <Data Name="ConnectedStandbyInProgress">false</Data>
  1652. <Data Name="SystemSleepTransitionsToOn">0</Data>
  1653. <Data Name="CsEntryScenarioInstanceId">0</Data>
  1654. </EventData>
  1655. </Event>
  1656.  
  1657. Log Name: System
  1658. Source: EventLog
  1659. Date: 8/23/2016 6:23:19 PM
  1660. Event ID: 6008
  1661. Task Category: None
  1662. Level: Error
  1663. Keywords: Classic
  1664. User: N/A
  1665. Computer: DESKTOP-D07KK79
  1666. Description:
  1667. The previous system shutdown at 6:17:00 PM on ‎8/‎23/‎2016 was unexpected.
  1668. Event Xml:
  1669. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1670. <System>
  1671. <Provider Name="EventLog" />
  1672. <EventID Qualifiers="32768">6008</EventID>
  1673. <Level>2</Level>
  1674. <Task>0</Task>
  1675. <Keywords>0x80000000000000</Keywords>
  1676. <TimeCreated SystemTime="2016-08-24T01:23:19.832359900Z" />
  1677. <EventRecordID>968</EventRecordID>
  1678. <Channel>System</Channel>
  1679. <Computer>DESKTOP-D07KK79</Computer>
  1680. <Security />
  1681. </System>
  1682. <EventData>
  1683. <Data>6:17:00 PM</Data>
  1684. <Data>‎8/‎23/‎2016</Data>
  1685. <Data>
  1686. </Data>
  1687. <Data>
  1688. </Data>
  1689. <Data>21</Data>
  1690. <Data>
  1691. </Data>
  1692. <Data>
  1693. </Data>
  1694. <Binary>E0070800020017001200110000007803E00708000300180001001100000078033C0000003C000000010000003C00000000000000B00400000100000000000000</Binary>
  1695. </EventData>
  1696. </Event>
  1697.  
  1698. Log Name: Application
  1699. Source: Application Error
  1700. Date: 8/23/2016 6:17:42 PM
  1701. Event ID: 1000
  1702. Task Category: (100)
  1703. Level: Error
  1704. Keywords: Classic
  1705. User: N/A
  1706. Computer: DESKTOP-D07KK79
  1707. Description:
  1708. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  1709. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  1710. Exception code: 0xc0000409
  1711. Fault offset: 0x000d96c2
  1712. Faulting process id: 0x1014
  1713. Faulting application start time: 0x01d1fda53ea50218
  1714. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  1715. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  1716. Report Id: 79a3f0c2-2b2e-445a-b02c-6ed62fd497f5
  1717. Faulting package full name:
  1718. Faulting package-relative application ID:
  1719. Event Xml:
  1720. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1721. <System>
  1722. <Provider Name="Application Error" />
  1723. <EventID Qualifiers="0">1000</EventID>
  1724. <Level>2</Level>
  1725. <Task>100</Task>
  1726. <Keywords>0x80000000000000</Keywords>
  1727. <TimeCreated SystemTime="2016-08-24T01:17:42.017341100Z" />
  1728. <EventRecordID>597</EventRecordID>
  1729. <Channel>Application</Channel>
  1730. <Computer>DESKTOP-D07KK79</Computer>
  1731. <Security />
  1732. </System>
  1733. <EventData>
  1734. <Data>DipAwayMode.exe</Data>
  1735. <Data>0.0.0.0</Data>
  1736. <Data>00000000</Data>
  1737. <Data>KERNELBASE.dll</Data>
  1738. <Data>10.0.14393.0</Data>
  1739. <Data>57898e34</Data>
  1740. <Data>c0000409</Data>
  1741. <Data>000d96c2</Data>
  1742. <Data>1014</Data>
  1743. <Data>01d1fda53ea50218</Data>
  1744. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  1745. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  1746. <Data>79a3f0c2-2b2e-445a-b02c-6ed62fd497f5</Data>
  1747. <Data>
  1748. </Data>
  1749. <Data>
  1750. </Data>
  1751. </EventData>
  1752. </Event>
  1753.  
  1754. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1755. Source: Microsoft-Windows-DeviceSetupManager
  1756. Date: 8/23/2016 6:17:04 PM
  1757. Event ID: 200
  1758. Task Category: None
  1759. Level: Warning
  1760. Keywords:
  1761. User: SYSTEM
  1762. Computer: DESKTOP-D07KK79
  1763. Description:
  1764. A connection to the Windows Update service could not be established.
  1765. Event Xml:
  1766. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1767. <System>
  1768. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1769. <EventID>200</EventID>
  1770. <Version>0</Version>
  1771. <Level>3</Level>
  1772. <Task>0</Task>
  1773. <Opcode>0</Opcode>
  1774. <Keywords>0x4000000000000000</Keywords>
  1775. <TimeCreated SystemTime="2016-08-24T01:17:04.271054700Z" />
  1776. <EventRecordID>202</EventRecordID>
  1777. <Correlation />
  1778. <Execution ProcessID="532" ThreadID="628" />
  1779. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1780. <Computer>DESKTOP-D07KK79</Computer>
  1781. <Security UserID="S-1-5-18" />
  1782. </System>
  1783. <EventData>
  1784. </EventData>
  1785. </Event>
  1786.  
  1787. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1788. Source: Microsoft-Windows-DeviceSetupManager
  1789. Date: 8/23/2016 6:17:04 PM
  1790. Event ID: 202
  1791. Task Category: None
  1792. Level: Warning
  1793. Keywords:
  1794. User: SYSTEM
  1795. Computer: DESKTOP-D07KK79
  1796. Description:
  1797. The Network List Manager reports no connectivity to the internet.
  1798. Event Xml:
  1799. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1800. <System>
  1801. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1802. <EventID>202</EventID>
  1803. <Version>0</Version>
  1804. <Level>3</Level>
  1805. <Task>0</Task>
  1806. <Opcode>0</Opcode>
  1807. <Keywords>0x4000000000000000</Keywords>
  1808. <TimeCreated SystemTime="2016-08-24T01:17:04.270964100Z" />
  1809. <EventRecordID>201</EventRecordID>
  1810. <Correlation />
  1811. <Execution ProcessID="532" ThreadID="628" />
  1812. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1813. <Computer>DESKTOP-D07KK79</Computer>
  1814. <Security UserID="S-1-5-18" />
  1815. </System>
  1816. <EventData>
  1817. </EventData>
  1818. </Event>
  1819.  
  1820. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1821. Source: Microsoft-Windows-DeviceSetupManager
  1822. Date: 8/23/2016 6:17:04 PM
  1823. Event ID: 200
  1824. Task Category: None
  1825. Level: Warning
  1826. Keywords:
  1827. User: SYSTEM
  1828. Computer: DESKTOP-D07KK79
  1829. Description:
  1830. A connection to the Windows Update service could not be established.
  1831. Event Xml:
  1832. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1833. <System>
  1834. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1835. <EventID>200</EventID>
  1836. <Version>0</Version>
  1837. <Level>3</Level>
  1838. <Task>0</Task>
  1839. <Opcode>0</Opcode>
  1840. <Keywords>0x4000000000000000</Keywords>
  1841. <TimeCreated SystemTime="2016-08-24T01:17:04.270915000Z" />
  1842. <EventRecordID>200</EventRecordID>
  1843. <Correlation />
  1844. <Execution ProcessID="532" ThreadID="1456" />
  1845. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1846. <Computer>DESKTOP-D07KK79</Computer>
  1847. <Security UserID="S-1-5-18" />
  1848. </System>
  1849. <EventData>
  1850. </EventData>
  1851. </Event>
  1852.  
  1853. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1854. Source: Microsoft-Windows-DeviceSetupManager
  1855. Date: 8/23/2016 6:17:04 PM
  1856. Event ID: 202
  1857. Task Category: None
  1858. Level: Warning
  1859. Keywords:
  1860. User: SYSTEM
  1861. Computer: DESKTOP-D07KK79
  1862. Description:
  1863. The Network List Manager reports no connectivity to the internet.
  1864. Event Xml:
  1865. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1866. <System>
  1867. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1868. <EventID>202</EventID>
  1869. <Version>0</Version>
  1870. <Level>3</Level>
  1871. <Task>0</Task>
  1872. <Opcode>0</Opcode>
  1873. <Keywords>0x4000000000000000</Keywords>
  1874. <TimeCreated SystemTime="2016-08-24T01:17:04.270839300Z" />
  1875. <EventRecordID>199</EventRecordID>
  1876. <Correlation />
  1877. <Execution ProcessID="532" ThreadID="1456" />
  1878. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1879. <Computer>DESKTOP-D07KK79</Computer>
  1880. <Security UserID="S-1-5-18" />
  1881. </System>
  1882. <EventData>
  1883. </EventData>
  1884. </Event>
  1885.  
  1886. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1887. Source: Microsoft-Windows-DeviceSetupManager
  1888. Date: 8/23/2016 6:17:01 PM
  1889. Event ID: 201
  1890. Task Category: None
  1891. Level: Warning
  1892. Keywords:
  1893. User: SYSTEM
  1894. Computer: DESKTOP-D07KK79
  1895. Description:
  1896. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  1897. Event Xml:
  1898. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1899. <System>
  1900. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1901. <EventID>201</EventID>
  1902. <Version>0</Version>
  1903. <Level>3</Level>
  1904. <Task>0</Task>
  1905. <Opcode>0</Opcode>
  1906. <Keywords>0x4000000000000000</Keywords>
  1907. <TimeCreated SystemTime="2016-08-24T01:17:01.269504300Z" />
  1908. <EventRecordID>196</EventRecordID>
  1909. <Correlation />
  1910. <Execution ProcessID="532" ThreadID="1456" />
  1911. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1912. <Computer>DESKTOP-D07KK79</Computer>
  1913. <Security UserID="S-1-5-18" />
  1914. </System>
  1915. <EventData>
  1916. </EventData>
  1917. </Event>
  1918.  
  1919. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1920. Source: Microsoft-Windows-DeviceSetupManager
  1921. Date: 8/23/2016 6:17:01 PM
  1922. Event ID: 202
  1923. Task Category: None
  1924. Level: Warning
  1925. Keywords:
  1926. User: SYSTEM
  1927. Computer: DESKTOP-D07KK79
  1928. Description:
  1929. The Network List Manager reports no connectivity to the internet.
  1930. Event Xml:
  1931. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1932. <System>
  1933. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1934. <EventID>202</EventID>
  1935. <Version>0</Version>
  1936. <Level>3</Level>
  1937. <Task>0</Task>
  1938. <Opcode>0</Opcode>
  1939. <Keywords>0x4000000000000000</Keywords>
  1940. <TimeCreated SystemTime="2016-08-24T01:17:01.269427100Z" />
  1941. <EventRecordID>194</EventRecordID>
  1942. <Correlation />
  1943. <Execution ProcessID="532" ThreadID="1456" />
  1944. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1945. <Computer>DESKTOP-D07KK79</Computer>
  1946. <Security UserID="S-1-5-18" />
  1947. </System>
  1948. <EventData>
  1949. </EventData>
  1950. </Event>
  1951.  
  1952. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1953. Source: Microsoft-Windows-DeviceSetupManager
  1954. Date: 8/23/2016 6:17:01 PM
  1955. Event ID: 201
  1956. Task Category: None
  1957. Level: Warning
  1958. Keywords:
  1959. User: SYSTEM
  1960. Computer: DESKTOP-D07KK79
  1961. Description:
  1962. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  1963. Event Xml:
  1964. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1965. <System>
  1966. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  1967. <EventID>201</EventID>
  1968. <Version>0</Version>
  1969. <Level>3</Level>
  1970. <Task>0</Task>
  1971. <Opcode>0</Opcode>
  1972. <Keywords>0x4000000000000000</Keywords>
  1973. <TimeCreated SystemTime="2016-08-24T01:17:01.269122300Z" />
  1974. <EventRecordID>193</EventRecordID>
  1975. <Correlation />
  1976. <Execution ProcessID="532" ThreadID="628" />
  1977. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  1978. <Computer>DESKTOP-D07KK79</Computer>
  1979. <Security UserID="S-1-5-18" />
  1980. </System>
  1981. <EventData>
  1982. </EventData>
  1983. </Event>
  1984.  
  1985. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  1986. Source: Microsoft-Windows-DeviceSetupManager
  1987. Date: 8/23/2016 6:17:01 PM
  1988. Event ID: 202
  1989. Task Category: None
  1990. Level: Warning
  1991. Keywords:
  1992. User: SYSTEM
  1993. Computer: DESKTOP-D07KK79
  1994. Description:
  1995. The Network List Manager reports no connectivity to the internet.
  1996. Event Xml:
  1997. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  1998. <System>
  1999. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  2000. <EventID>202</EventID>
  2001. <Version>0</Version>
  2002. <Level>3</Level>
  2003. <Task>0</Task>
  2004. <Opcode>0</Opcode>
  2005. <Keywords>0x4000000000000000</Keywords>
  2006. <TimeCreated SystemTime="2016-08-24T01:17:01.269053000Z" />
  2007. <EventRecordID>192</EventRecordID>
  2008. <Correlation />
  2009. <Execution ProcessID="532" ThreadID="628" />
  2010. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  2011. <Computer>DESKTOP-D07KK79</Computer>
  2012. <Security UserID="S-1-5-18" />
  2013. </System>
  2014. <EventData>
  2015. </EventData>
  2016. </Event>
  2017.  
  2018. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  2019. Source: Microsoft-Windows-DeviceSetupManager
  2020. Date: 8/23/2016 6:17:00 PM
  2021. Event ID: 200
  2022. Task Category: None
  2023. Level: Warning
  2024. Keywords:
  2025. User: SYSTEM
  2026. Computer: DESKTOP-D07KK79
  2027. Description:
  2028. A connection to the Windows Update service could not be established.
  2029. Event Xml:
  2030. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2031. <System>
  2032. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  2033. <EventID>200</EventID>
  2034. <Version>0</Version>
  2035. <Level>3</Level>
  2036. <Task>0</Task>
  2037. <Opcode>0</Opcode>
  2038. <Keywords>0x4000000000000000</Keywords>
  2039. <TimeCreated SystemTime="2016-08-24T01:17:00.949626800Z" />
  2040. <EventRecordID>191</EventRecordID>
  2041. <Correlation />
  2042. <Execution ProcessID="532" ThreadID="1456" />
  2043. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  2044. <Computer>DESKTOP-D07KK79</Computer>
  2045. <Security UserID="S-1-5-18" />
  2046. </System>
  2047. <EventData>
  2048. </EventData>
  2049. </Event>
  2050.  
  2051. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  2052. Source: Microsoft-Windows-DeviceSetupManager
  2053. Date: 8/23/2016 6:17:00 PM
  2054. Event ID: 202
  2055. Task Category: None
  2056. Level: Warning
  2057. Keywords:
  2058. User: SYSTEM
  2059. Computer: DESKTOP-D07KK79
  2060. Description:
  2061. The Network List Manager reports no connectivity to the internet.
  2062. Event Xml:
  2063. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2064. <System>
  2065. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  2066. <EventID>202</EventID>
  2067. <Version>0</Version>
  2068. <Level>3</Level>
  2069. <Task>0</Task>
  2070. <Opcode>0</Opcode>
  2071. <Keywords>0x4000000000000000</Keywords>
  2072. <TimeCreated SystemTime="2016-08-24T01:17:00.949467000Z" />
  2073. <EventRecordID>190</EventRecordID>
  2074. <Correlation />
  2075. <Execution ProcessID="532" ThreadID="1456" />
  2076. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  2077. <Computer>DESKTOP-D07KK79</Computer>
  2078. <Security UserID="S-1-5-18" />
  2079. </System>
  2080. <EventData>
  2081. </EventData>
  2082. </Event>
  2083.  
  2084. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  2085. Source: Microsoft-Windows-DeviceSetupManager
  2086. Date: 8/23/2016 6:17:00 PM
  2087. Event ID: 200
  2088. Task Category: None
  2089. Level: Warning
  2090. Keywords:
  2091. User: SYSTEM
  2092. Computer: DESKTOP-D07KK79
  2093. Description:
  2094. A connection to the Windows Update service could not be established.
  2095. Event Xml:
  2096. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2097. <System>
  2098. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  2099. <EventID>200</EventID>
  2100. <Version>0</Version>
  2101. <Level>3</Level>
  2102. <Task>0</Task>
  2103. <Opcode>0</Opcode>
  2104. <Keywords>0x4000000000000000</Keywords>
  2105. <TimeCreated SystemTime="2016-08-24T01:17:00.949237900Z" />
  2106. <EventRecordID>189</EventRecordID>
  2107. <Correlation />
  2108. <Execution ProcessID="532" ThreadID="628" />
  2109. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  2110. <Computer>DESKTOP-D07KK79</Computer>
  2111. <Security UserID="S-1-5-18" />
  2112. </System>
  2113. <EventData>
  2114. </EventData>
  2115. </Event>
  2116.  
  2117. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  2118. Source: Microsoft-Windows-DeviceSetupManager
  2119. Date: 8/23/2016 6:17:00 PM
  2120. Event ID: 202
  2121. Task Category: None
  2122. Level: Warning
  2123. Keywords:
  2124. User: SYSTEM
  2125. Computer: DESKTOP-D07KK79
  2126. Description:
  2127. The Network List Manager reports no connectivity to the internet.
  2128. Event Xml:
  2129. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2130. <System>
  2131. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  2132. <EventID>202</EventID>
  2133. <Version>0</Version>
  2134. <Level>3</Level>
  2135. <Task>0</Task>
  2136. <Opcode>0</Opcode>
  2137. <Keywords>0x4000000000000000</Keywords>
  2138. <TimeCreated SystemTime="2016-08-24T01:17:00.949131600Z" />
  2139. <EventRecordID>188</EventRecordID>
  2140. <Correlation />
  2141. <Execution ProcessID="532" ThreadID="628" />
  2142. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  2143. <Computer>DESKTOP-D07KK79</Computer>
  2144. <Security UserID="S-1-5-18" />
  2145. </System>
  2146. <EventData>
  2147. </EventData>
  2148. </Event>
  2149.  
  2150. Log Name: System
  2151. Source: Microsoft-Windows-Kernel-PnP
  2152. Date: 8/23/2016 6:16:44 PM
  2153. Event ID: 219
  2154. Task Category: (212)
  2155. Level: Warning
  2156. Keywords:
  2157. User: SYSTEM
  2158. Computer: DESKTOP-D07KK79
  2159. Description:
  2160. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  2161. Event Xml:
  2162. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2163. <System>
  2164. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  2165. <EventID>219</EventID>
  2166. <Version>0</Version>
  2167. <Level>3</Level>
  2168. <Task>212</Task>
  2169. <Opcode>0</Opcode>
  2170. <Keywords>0x8000000000000000</Keywords>
  2171. <TimeCreated SystemTime="2016-08-24T01:16:44.892753100Z" />
  2172. <EventRecordID>932</EventRecordID>
  2173. <Correlation />
  2174. <Execution ProcessID="4" ThreadID="140" />
  2175. <Channel>System</Channel>
  2176. <Computer>DESKTOP-D07KK79</Computer>
  2177. <Security UserID="S-1-5-18" />
  2178. </System>
  2179. <EventData>
  2180. <Data Name="DriverNameLength">24</Data>
  2181. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  2182. <Data Name="Status">3221226341</Data>
  2183. <Data Name="FailureNameLength">14</Data>
  2184. <Data Name="FailureName">\Driver\WUDFRd</Data>
  2185. <Data Name="Version">0</Data>
  2186. </EventData>
  2187. </Event>
  2188.  
  2189. Log Name: Security
  2190. Source: Microsoft-Windows-Eventlog
  2191. Date: 8/23/2016 6:17:01 PM
  2192. Event ID: 1101
  2193. Task Category: Event processing
  2194. Level: Error
  2195. Keywords: Audit Success
  2196. User: N/A
  2197. Computer: DESKTOP-D07KK79
  2198. Description:
  2199. Audit events have been dropped by the transport. 0
  2200. Event Xml:
  2201. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2202. <System>
  2203. <Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
  2204. <EventID>1101</EventID>
  2205. <Version>0</Version>
  2206. <Level>2</Level>
  2207. <Task>101</Task>
  2208. <Opcode>0</Opcode>
  2209. <Keywords>0x4020000000000000</Keywords>
  2210. <TimeCreated SystemTime="2016-08-24T01:17:01.981807000Z" />
  2211. <EventRecordID>1174</EventRecordID>
  2212. <Correlation />
  2213. <Execution ProcessID="1472" ThreadID="2148" />
  2214. <Channel>Security</Channel>
  2215. <Computer>DESKTOP-D07KK79</Computer>
  2216. <Security />
  2217. </System>
  2218. <UserData>
  2219. <AuditEventsDropped xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
  2220. <Reason>0</Reason>
  2221. </AuditEventsDropped>
  2222. </UserData>
  2223. </Event>
  2224.  
  2225. Log Name: System
  2226. Source: Microsoft-Windows-Kernel-Power
  2227. Date: 8/23/2016 6:16:44 PM
  2228. Event ID: 41
  2229. Task Category: (63)
  2230. Level: Critical
  2231. Keywords: (70368744177664),(2)
  2232. User: SYSTEM
  2233. Computer: DESKTOP-D07KK79
  2234. Description:
  2235. The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
  2236. Event Xml:
  2237. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2238. <System>
  2239. <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
  2240. <EventID>41</EventID>
  2241. <Version>4</Version>
  2242. <Level>1</Level>
  2243. <Task>63</Task>
  2244. <Opcode>0</Opcode>
  2245. <Keywords>0x8000400000000002</Keywords>
  2246. <TimeCreated SystemTime="2016-08-24T01:16:44.697018800Z" />
  2247. <EventRecordID>929</EventRecordID>
  2248. <Correlation />
  2249. <Execution ProcessID="4" ThreadID="8" />
  2250. <Channel>System</Channel>
  2251. <Computer>DESKTOP-D07KK79</Computer>
  2252. <Security UserID="S-1-5-18" />
  2253. </System>
  2254. <EventData>
  2255. <Data Name="BugcheckCode">0</Data>
  2256. <Data Name="BugcheckParameter1">0x0</Data>
  2257. <Data Name="BugcheckParameter2">0x0</Data>
  2258. <Data Name="BugcheckParameter3">0x0</Data>
  2259. <Data Name="BugcheckParameter4">0x0</Data>
  2260. <Data Name="SleepInProgress">0</Data>
  2261. <Data Name="PowerButtonTimestamp">0</Data>
  2262. <Data Name="BootAppStatus">0</Data>
  2263. <Data Name="Checkpoint">0</Data>
  2264. <Data Name="ConnectedStandbyInProgress">false</Data>
  2265. <Data Name="SystemSleepTransitionsToOn">0</Data>
  2266. <Data Name="CsEntryScenarioInstanceId">0</Data>
  2267. </EventData>
  2268. </Event>
  2269.  
  2270. Log Name: System
  2271. Source: EventLog
  2272. Date: 8/23/2016 6:17:00 PM
  2273. Event ID: 6008
  2274. Task Category: None
  2275. Level: Error
  2276. Keywords: Classic
  2277. User: N/A
  2278. Computer: DESKTOP-D07KK79
  2279. Description:
  2280. The previous system shutdown at 5:40:29 PM on ‎8/‎23/‎2016 was unexpected.
  2281. Event Xml:
  2282. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2283. <System>
  2284. <Provider Name="EventLog" />
  2285. <EventID Qualifiers="32768">6008</EventID>
  2286. <Level>2</Level>
  2287. <Task>0</Task>
  2288. <Keywords>0x80000000000000</Keywords>
  2289. <TimeCreated SystemTime="2016-08-24T01:17:00.886710300Z" />
  2290. <EventRecordID>912</EventRecordID>
  2291. <Channel>System</Channel>
  2292. <Computer>DESKTOP-D07KK79</Computer>
  2293. <Security />
  2294. </System>
  2295. <EventData>
  2296. <Data>5:40:29 PM</Data>
  2297. <Data>‎8/‎23/‎2016</Data>
  2298. <Data>
  2299. </Data>
  2300. <Data>
  2301. </Data>
  2302. <Data>2413</Data>
  2303. <Data>
  2304. </Data>
  2305. <Data>
  2306. </Data>
  2307. <Binary>E007080002001700110028001D00D200E007080003001800000028001D00D200600900003C000000010000006009000001000000B00400000100000000000000</Binary>
  2308. </EventData>
  2309. </Event>
  2310.  
  2311. Log Name: Application
  2312. Source: Microsoft-Windows-Search
  2313. Date: 8/23/2016 5:29:04 PM
  2314. Event ID: 3104
  2315. Task Category: Gatherer
  2316. Level: Error
  2317. Keywords: Classic
  2318. User: N/A
  2319. Computer: DESKTOP-D07KK79
  2320. Description:
  2321. Enumerating user sessions to generate filter pools failed.
  2322.  
  2323. Details:
  2324. (HRESULT : 0x80040210) (0x80040210)
  2325.  
  2326. Event Xml:
  2327. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2328. <System>
  2329. <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
  2330. <EventID Qualifiers="49152">3104</EventID>
  2331. <Version>0</Version>
  2332. <Level>2</Level>
  2333. <Task>3</Task>
  2334. <Opcode>0</Opcode>
  2335. <Keywords>0x80000000000000</Keywords>
  2336. <TimeCreated SystemTime="2016-08-24T00:29:04.705410300Z" />
  2337. <EventRecordID>575</EventRecordID>
  2338. <Correlation />
  2339. <Execution ProcessID="0" ThreadID="0" />
  2340. <Channel>Application</Channel>
  2341. <Computer>DESKTOP-D07KK79</Computer>
  2342. <Security />
  2343. </System>
  2344. <EventData>
  2345. <Data>
  2346.  
  2347. Details:
  2348. (HRESULT : 0x80040210) (0x80040210)
  2349. </Data>
  2350. </EventData>
  2351. </Event>
  2352.  
  2353. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2354. Source: Microsoft-Windows-AppModel-Runtime
  2355. Date: 8/23/2016 5:26:04 PM
  2356. Event ID: 69
  2357. Task Category: None
  2358. Level: Error
  2359. Keywords: (70368744177664),Process
  2360. User: SYSTEM
  2361. Computer: DESKTOP-D07KK79
  2362. Description:
  2363. Failed with 0x490 modifying AppModel Runtime status for package D52A8D61.FarmVille2CountryEscape_5.5.1001.0_x86__jwbwg6xx0377a for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2364. Event Xml:
  2365. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2366. <System>
  2367. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2368. <EventID>69</EventID>
  2369. <Version>0</Version>
  2370. <Level>2</Level>
  2371. <Task>0</Task>
  2372. <Opcode>0</Opcode>
  2373. <Keywords>0x2000400000000001</Keywords>
  2374. <TimeCreated SystemTime="2016-08-24T00:26:04.476922400Z" />
  2375. <EventRecordID>315</EventRecordID>
  2376. <Correlation ActivityID="{7E5F5F39-FD9A-0007-7078-5F7E9AFDD101}" />
  2377. <Execution ProcessID="3504" ThreadID="8608" />
  2378. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2379. <Computer>DESKTOP-D07KK79</Computer>
  2380. <Security UserID="S-1-5-18" />
  2381. </System>
  2382. <EventData>
  2383. <Data Name="ErrorCode">1168</Data>
  2384. <Data Name="PackageFullName">D52A8D61.FarmVille2CountryEscape_5.5.1001.0_x86__jwbwg6xx0377a</Data>
  2385. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2386. <Data Name="DesiredStatus">32</Data>
  2387. <Data Name="CurrentStatus">0</Data>
  2388. </EventData>
  2389. </Event>
  2390.  
  2391. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2392. Source: Microsoft-Windows-AppModel-Runtime
  2393. Date: 8/23/2016 5:25:41 PM
  2394. Event ID: 69
  2395. Task Category: None
  2396. Level: Error
  2397. Keywords: (70368744177664),Process
  2398. User: SYSTEM
  2399. Computer: DESKTOP-D07KK79
  2400. Description:
  2401. Failed with 0x490 modifying AppModel Runtime status for package GAMELOFTSA.Asphalt8Airborne_2.6.0.6_x86__0pp20fcewvvtj for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2402. Event Xml:
  2403. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2404. <System>
  2405. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2406. <EventID>69</EventID>
  2407. <Version>0</Version>
  2408. <Level>2</Level>
  2409. <Task>0</Task>
  2410. <Opcode>0</Opcode>
  2411. <Keywords>0x2000400000000001</Keywords>
  2412. <TimeCreated SystemTime="2016-08-24T00:25:41.691625600Z" />
  2413. <EventRecordID>313</EventRecordID>
  2414. <Correlation ActivityID="{7E5F5F39-FD9A-0007-1977-5F7E9AFDD101}" />
  2415. <Execution ProcessID="3504" ThreadID="8608" />
  2416. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2417. <Computer>DESKTOP-D07KK79</Computer>
  2418. <Security UserID="S-1-5-18" />
  2419. </System>
  2420. <EventData>
  2421. <Data Name="ErrorCode">1168</Data>
  2422. <Data Name="PackageFullName">GAMELOFTSA.Asphalt8Airborne_2.6.0.6_x86__0pp20fcewvvtj</Data>
  2423. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2424. <Data Name="DesiredStatus">32</Data>
  2425. <Data Name="CurrentStatus">0</Data>
  2426. </EventData>
  2427. </Event>
  2428.  
  2429. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2430. Source: Microsoft-Windows-AppModel-Runtime
  2431. Date: 8/23/2016 5:25:41 PM
  2432. Event ID: 69
  2433. Task Category: None
  2434. Level: Error
  2435. Keywords: (70368744177664),Process
  2436. User: SYSTEM
  2437. Computer: DESKTOP-D07KK79
  2438. Description:
  2439. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.VCLibs.120.00_12.0.21005.1_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2440. Event Xml:
  2441. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2442. <System>
  2443. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2444. <EventID>69</EventID>
  2445. <Version>0</Version>
  2446. <Level>2</Level>
  2447. <Task>0</Task>
  2448. <Opcode>0</Opcode>
  2449. <Keywords>0x2000400000000001</Keywords>
  2450. <TimeCreated SystemTime="2016-08-24T00:25:41.190420200Z" />
  2451. <EventRecordID>311</EventRecordID>
  2452. <Correlation ActivityID="{7E5F5F39-FD9A-0001-5A76-5F7E9AFDD101}" />
  2453. <Execution ProcessID="3504" ThreadID="8716" />
  2454. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2455. <Computer>DESKTOP-D07KK79</Computer>
  2456. <Security UserID="S-1-5-18" />
  2457. </System>
  2458. <EventData>
  2459. <Data Name="ErrorCode">1168</Data>
  2460. <Data Name="PackageFullName">Microsoft.VCLibs.120.00_12.0.21005.1_x64__8wekyb3d8bbwe</Data>
  2461. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2462. <Data Name="DesiredStatus">32</Data>
  2463. <Data Name="CurrentStatus">0</Data>
  2464. </EventData>
  2465. </Event>
  2466.  
  2467. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2468. Source: Microsoft-Windows-AppModel-Runtime
  2469. Date: 8/23/2016 5:25:40 PM
  2470. Event ID: 69
  2471. Task Category: None
  2472. Level: Error
  2473. Keywords: (70368744177664),Process
  2474. User: SYSTEM
  2475. Computer: DESKTOP-D07KK79
  2476. Description:
  2477. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.VCLibs.120.00_12.0.21005.1_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2478. Event Xml:
  2479. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2480. <System>
  2481. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2482. <EventID>69</EventID>
  2483. <Version>0</Version>
  2484. <Level>2</Level>
  2485. <Task>0</Task>
  2486. <Opcode>0</Opcode>
  2487. <Keywords>0x2000400000000001</Keywords>
  2488. <TimeCreated SystemTime="2016-08-24T00:25:40.920524600Z" />
  2489. <EventRecordID>309</EventRecordID>
  2490. <Correlation ActivityID="{7E5F5F39-FD9A-0000-977E-5F7E9AFDD101}" />
  2491. <Execution ProcessID="3504" ThreadID="8608" />
  2492. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2493. <Computer>DESKTOP-D07KK79</Computer>
  2494. <Security UserID="S-1-5-18" />
  2495. </System>
  2496. <EventData>
  2497. <Data Name="ErrorCode">1168</Data>
  2498. <Data Name="PackageFullName">Microsoft.VCLibs.120.00_12.0.21005.1_x86__8wekyb3d8bbwe</Data>
  2499. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2500. <Data Name="DesiredStatus">32</Data>
  2501. <Data Name="CurrentStatus">0</Data>
  2502. </EventData>
  2503. </Event>
  2504.  
  2505. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2506. Source: Microsoft-Windows-AppModel-Runtime
  2507. Date: 8/23/2016 5:24:55 PM
  2508. Event ID: 69
  2509. Task Category: None
  2510. Level: Error
  2511. Keywords: (70368744177664),Process
  2512. User: SYSTEM
  2513. Computer: DESKTOP-D07KK79
  2514. Description:
  2515. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.ZuneVideo_3.6.22511.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2516. Event Xml:
  2517. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2518. <System>
  2519. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2520. <EventID>69</EventID>
  2521. <Version>0</Version>
  2522. <Level>2</Level>
  2523. <Task>0</Task>
  2524. <Opcode>0</Opcode>
  2525. <Keywords>0x2000400000000001</Keywords>
  2526. <TimeCreated SystemTime="2016-08-24T00:24:55.131548100Z" />
  2527. <EventRecordID>305</EventRecordID>
  2528. <Correlation ActivityID="{7E5F5F39-FD9A-0006-8675-5F7E9AFDD101}" />
  2529. <Execution ProcessID="3504" ThreadID="8608" />
  2530. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2531. <Computer>DESKTOP-D07KK79</Computer>
  2532. <Security UserID="S-1-5-18" />
  2533. </System>
  2534. <EventData>
  2535. <Data Name="ErrorCode">1168</Data>
  2536. <Data Name="PackageFullName">Microsoft.ZuneVideo_3.6.22511.0_x64__8wekyb3d8bbwe</Data>
  2537. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2538. <Data Name="DesiredStatus">32</Data>
  2539. <Data Name="CurrentStatus">0</Data>
  2540. </EventData>
  2541. </Event>
  2542.  
  2543. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2544. Source: Microsoft-Windows-AppModel-Runtime
  2545. Date: 8/23/2016 5:24:45 PM
  2546. Event ID: 69
  2547. Task Category: None
  2548. Level: Error
  2549. Keywords: (70368744177664),Process
  2550. User: SYSTEM
  2551. Computer: DESKTOP-D07KK79
  2552. Description:
  2553. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsCamera_2016.816.20.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2554. Event Xml:
  2555. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2556. <System>
  2557. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2558. <EventID>69</EventID>
  2559. <Version>0</Version>
  2560. <Level>2</Level>
  2561. <Task>0</Task>
  2562. <Opcode>0</Opcode>
  2563. <Keywords>0x2000400000000001</Keywords>
  2564. <TimeCreated SystemTime="2016-08-24T00:24:45.260619400Z" />
  2565. <EventRecordID>301</EventRecordID>
  2566. <Correlation ActivityID="{7E5F5F39-FD9A-0001-D675-5F7E9AFDD101}" />
  2567. <Execution ProcessID="3504" ThreadID="8716" />
  2568. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2569. <Computer>DESKTOP-D07KK79</Computer>
  2570. <Security UserID="S-1-5-18" />
  2571. </System>
  2572. <EventData>
  2573. <Data Name="ErrorCode">1168</Data>
  2574. <Data Name="PackageFullName">Microsoft.WindowsCamera_2016.816.20.0_x64__8wekyb3d8bbwe</Data>
  2575. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2576. <Data Name="DesiredStatus">32</Data>
  2577. <Data Name="CurrentStatus">0</Data>
  2578. </EventData>
  2579. </Event>
  2580.  
  2581. Log Name: Application
  2582. Source: Microsoft-Windows-Immersive-Shell
  2583. Date: 8/23/2016 5:24:32 PM
  2584. Event ID: 5973
  2585. Task Category: (5973)
  2586. Level: Error
  2587. Keywords:
  2588. User: DESKTOP-D07KK79\Enzo
  2589. Computer: DESKTOP-D07KK79
  2590. Description:
  2591. Activation of app Microsoft.WindowsMaps_8wekyb3d8bbwe!App failed with error: This app does not support the contract specified or is not installed. See the Microsoft-Windows-TWinUI/Operational log for additional information.
  2592. Event Xml:
  2593. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2594. <System>
  2595. <Provider Name="Microsoft-Windows-Immersive-Shell" Guid="{315A8872-923E-4EA2-9889-33CD4754BF64}" />
  2596. <EventID>5973</EventID>
  2597. <Version>0</Version>
  2598. <Level>2</Level>
  2599. <Task>5973</Task>
  2600. <Opcode>0</Opcode>
  2601. <Keywords>0x2000000000000000</Keywords>
  2602. <TimeCreated SystemTime="2016-08-24T00:24:32.421495300Z" />
  2603. <EventRecordID>572</EventRecordID>
  2604. <Correlation />
  2605. <Execution ProcessID="3880" ThreadID="3948" />
  2606. <Channel>Application</Channel>
  2607. <Computer>DESKTOP-D07KK79</Computer>
  2608. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  2609. </System>
  2610. <EventData>
  2611. <Data Name="AppId">Microsoft.WindowsMaps_8wekyb3d8bbwe!App</Data>
  2612. <Data Name="ErrorCode">-2144927148</Data>
  2613. </EventData>
  2614. </Event>
  2615.  
  2616. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2617. Source: Microsoft-Windows-AppModel-Runtime
  2618. Date: 8/23/2016 5:24:29 PM
  2619. Event ID: 69
  2620. Task Category: None
  2621. Level: Error
  2622. Keywords: (70368744177664),Process
  2623. User: SYSTEM
  2624. Computer: DESKTOP-D07KK79
  2625. Description:
  2626. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsMaps_5.1608.2311.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2627. Event Xml:
  2628. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2629. <System>
  2630. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2631. <EventID>69</EventID>
  2632. <Version>0</Version>
  2633. <Level>2</Level>
  2634. <Task>0</Task>
  2635. <Opcode>0</Opcode>
  2636. <Keywords>0x2000400000000001</Keywords>
  2637. <TimeCreated SystemTime="2016-08-24T00:24:29.359668900Z" />
  2638. <EventRecordID>296</EventRecordID>
  2639. <Correlation ActivityID="{7E5F5F39-FD9A-0002-A17B-5F7E9AFDD101}" />
  2640. <Execution ProcessID="3504" ThreadID="8608" />
  2641. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2642. <Computer>DESKTOP-D07KK79</Computer>
  2643. <Security UserID="S-1-5-18" />
  2644. </System>
  2645. <EventData>
  2646. <Data Name="ErrorCode">1168</Data>
  2647. <Data Name="PackageFullName">Microsoft.WindowsMaps_5.1608.2311.0_x64__8wekyb3d8bbwe</Data>
  2648. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2649. <Data Name="DesiredStatus">32</Data>
  2650. <Data Name="CurrentStatus">0</Data>
  2651. </EventData>
  2652. </Event>
  2653.  
  2654. Log Name: Application
  2655. Source: Microsoft-Windows-Immersive-Shell
  2656. Date: 8/23/2016 5:24:03 PM
  2657. Event ID: 5973
  2658. Task Category: (5973)
  2659. Level: Error
  2660. Keywords:
  2661. User: DESKTOP-D07KK79\Enzo
  2662. Computer: DESKTOP-D07KK79
  2663. Description:
  2664. Activation of app Microsoft.BingWeather_8wekyb3d8bbwe!App failed with error: This app does not support the contract specified or is not installed. See the Microsoft-Windows-TWinUI/Operational log for additional information.
  2665. Event Xml:
  2666. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2667. <System>
  2668. <Provider Name="Microsoft-Windows-Immersive-Shell" Guid="{315A8872-923E-4EA2-9889-33CD4754BF64}" />
  2669. <EventID>5973</EventID>
  2670. <Version>0</Version>
  2671. <Level>2</Level>
  2672. <Task>5973</Task>
  2673. <Opcode>0</Opcode>
  2674. <Keywords>0x2000000000000000</Keywords>
  2675. <TimeCreated SystemTime="2016-08-24T00:24:03.538322600Z" />
  2676. <EventRecordID>571</EventRecordID>
  2677. <Correlation />
  2678. <Execution ProcessID="3880" ThreadID="3948" />
  2679. <Channel>Application</Channel>
  2680. <Computer>DESKTOP-D07KK79</Computer>
  2681. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  2682. </System>
  2683. <EventData>
  2684. <Data Name="AppId">Microsoft.BingWeather_8wekyb3d8bbwe!App</Data>
  2685. <Data Name="ErrorCode">-2144927148</Data>
  2686. </EventData>
  2687. </Event>
  2688.  
  2689. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2690. Source: Microsoft-Windows-AppModel-Runtime
  2691. Date: 8/23/2016 5:24:01 PM
  2692. Event ID: 69
  2693. Task Category: None
  2694. Level: Error
  2695. Keywords: (70368744177664),Process
  2696. User: SYSTEM
  2697. Computer: DESKTOP-D07KK79
  2698. Description:
  2699. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.BingWeather_4.13.47.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2700. Event Xml:
  2701. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2702. <System>
  2703. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2704. <EventID>69</EventID>
  2705. <Version>0</Version>
  2706. <Level>2</Level>
  2707. <Task>0</Task>
  2708. <Opcode>0</Opcode>
  2709. <Keywords>0x2000400000000001</Keywords>
  2710. <TimeCreated SystemTime="2016-08-24T00:24:01.335728300Z" />
  2711. <EventRecordID>294</EventRecordID>
  2712. <Correlation ActivityID="{7E5F5F39-FD9A-0002-B679-5F7E9AFDD101}" />
  2713. <Execution ProcessID="3504" ThreadID="8716" />
  2714. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2715. <Computer>DESKTOP-D07KK79</Computer>
  2716. <Security UserID="S-1-5-18" />
  2717. </System>
  2718. <EventData>
  2719. <Data Name="ErrorCode">1168</Data>
  2720. <Data Name="PackageFullName">Microsoft.BingWeather_4.13.47.0_x86__8wekyb3d8bbwe</Data>
  2721. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2722. <Data Name="DesiredStatus">32</Data>
  2723. <Data Name="CurrentStatus">0</Data>
  2724. </EventData>
  2725. </Event>
  2726.  
  2727. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2728. Source: Microsoft-Windows-AppModel-Runtime
  2729. Date: 8/23/2016 5:23:57 PM
  2730. Event ID: 69
  2731. Task Category: None
  2732. Level: Error
  2733. Keywords: (70368744177664),Process
  2734. User: SYSTEM
  2735. Computer: DESKTOP-D07KK79
  2736. Description:
  2737. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2738. Event Xml:
  2739. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2740. <System>
  2741. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2742. <EventID>69</EventID>
  2743. <Version>0</Version>
  2744. <Level>2</Level>
  2745. <Task>0</Task>
  2746. <Opcode>0</Opcode>
  2747. <Keywords>0x2000400000000001</Keywords>
  2748. <TimeCreated SystemTime="2016-08-24T00:23:57.885242400Z" />
  2749. <EventRecordID>290</EventRecordID>
  2750. <Correlation ActivityID="{7E5F5F39-FD9A-0007-3575-5F7E9AFDD101}" />
  2751. <Execution ProcessID="3504" ThreadID="8608" />
  2752. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2753. <Computer>DESKTOP-D07KK79</Computer>
  2754. <Security UserID="S-1-5-18" />
  2755. </System>
  2756. <EventData>
  2757. <Data Name="ErrorCode">1168</Data>
  2758. <Data Name="PackageFullName">Microsoft.SkypeApp_11.7.102.0_x64__kzf8qxf38zg5c</Data>
  2759. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2760. <Data Name="DesiredStatus">32</Data>
  2761. <Data Name="CurrentStatus">0</Data>
  2762. </EventData>
  2763. </Event>
  2764.  
  2765. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2766. Source: Microsoft-Windows-AppModel-Runtime
  2767. Date: 8/23/2016 5:23:39 PM
  2768. Event ID: 69
  2769. Task Category: None
  2770. Level: Error
  2771. Keywords: (70368744177664),Process
  2772. User: SYSTEM
  2773. Computer: DESKTOP-D07KK79
  2774. Description:
  2775. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Getstarted_4.0.9.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2776. Event Xml:
  2777. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2778. <System>
  2779. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2780. <EventID>69</EventID>
  2781. <Version>0</Version>
  2782. <Level>2</Level>
  2783. <Task>0</Task>
  2784. <Opcode>0</Opcode>
  2785. <Keywords>0x2000400000000001</Keywords>
  2786. <TimeCreated SystemTime="2016-08-24T00:23:39.722698100Z" />
  2787. <EventRecordID>287</EventRecordID>
  2788. <Correlation ActivityID="{7E5F5F39-FD9A-0007-E774-5F7E9AFDD101}" />
  2789. <Execution ProcessID="3504" ThreadID="8716" />
  2790. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2791. <Computer>DESKTOP-D07KK79</Computer>
  2792. <Security UserID="S-1-5-18" />
  2793. </System>
  2794. <EventData>
  2795. <Data Name="ErrorCode">1168</Data>
  2796. <Data Name="PackageFullName">Microsoft.Getstarted_4.0.9.0_x64__8wekyb3d8bbwe</Data>
  2797. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2798. <Data Name="DesiredStatus">32</Data>
  2799. <Data Name="CurrentStatus">0</Data>
  2800. </EventData>
  2801. </Event>
  2802.  
  2803. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2804. Source: Microsoft-Windows-AppModel-Runtime
  2805. Date: 8/23/2016 5:23:07 PM
  2806. Event ID: 69
  2807. Task Category: None
  2808. Level: Error
  2809. Keywords: (70368744177664),Process
  2810. User: SYSTEM
  2811. Computer: DESKTOP-D07KK79
  2812. Description:
  2813. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2814. Event Xml:
  2815. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2816. <System>
  2817. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2818. <EventID>69</EventID>
  2819. <Version>0</Version>
  2820. <Level>2</Level>
  2821. <Task>0</Task>
  2822. <Opcode>0</Opcode>
  2823. <Keywords>0x2000400000000001</Keywords>
  2824. <TimeCreated SystemTime="2016-08-24T00:23:07.844551900Z" />
  2825. <EventRecordID>285</EventRecordID>
  2826. <Correlation ActivityID="{7E5F5F39-FD9A-0007-6974-5F7E9AFDD101}" />
  2827. <Execution ProcessID="3504" ThreadID="8608" />
  2828. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2829. <Computer>DESKTOP-D07KK79</Computer>
  2830. <Security UserID="S-1-5-18" />
  2831. </System>
  2832. <EventData>
  2833. <Data Name="ErrorCode">1168</Data>
  2834. <Data Name="PackageFullName">Microsoft.ZuneMusic_3.6.23041.0_x64__8wekyb3d8bbwe</Data>
  2835. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2836. <Data Name="DesiredStatus">32</Data>
  2837. <Data Name="CurrentStatus">0</Data>
  2838. </EventData>
  2839. </Event>
  2840.  
  2841. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2842. Source: Microsoft-Windows-AppModel-Runtime
  2843. Date: 8/23/2016 5:22:43 PM
  2844. Event ID: 69
  2845. Task Category: None
  2846. Level: Error
  2847. Keywords: (70368744177664),Process
  2848. User: SYSTEM
  2849. Computer: DESKTOP-D07KK79
  2850. Description:
  2851. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsStore_11607.1001.51.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2852. Event Xml:
  2853. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2854. <System>
  2855. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2856. <EventID>69</EventID>
  2857. <Version>0</Version>
  2858. <Level>2</Level>
  2859. <Task>0</Task>
  2860. <Opcode>0</Opcode>
  2861. <Keywords>0x2000400000000001</Keywords>
  2862. <TimeCreated SystemTime="2016-08-24T00:22:43.492631600Z" />
  2863. <EventRecordID>281</EventRecordID>
  2864. <Correlation ActivityID="{7E5F5F39-FD9A-0003-966F-5F7E9AFDD101}" />
  2865. <Execution ProcessID="3504" ThreadID="8608" />
  2866. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2867. <Computer>DESKTOP-D07KK79</Computer>
  2868. <Security UserID="S-1-5-18" />
  2869. </System>
  2870. <EventData>
  2871. <Data Name="ErrorCode">1168</Data>
  2872. <Data Name="PackageFullName">Microsoft.WindowsStore_11607.1001.51.0_x64__8wekyb3d8bbwe</Data>
  2873. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2874. <Data Name="DesiredStatus">32</Data>
  2875. <Data Name="CurrentStatus">0</Data>
  2876. </EventData>
  2877. </Event>
  2878.  
  2879. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2880. Source: Microsoft-Windows-AppModel-Runtime
  2881. Date: 8/23/2016 5:22:16 PM
  2882. Event ID: 69
  2883. Task Category: None
  2884. Level: Error
  2885. Keywords: (70368744177664),Process
  2886. User: SYSTEM
  2887. Computer: DESKTOP-D07KK79
  2888. Description:
  2889. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftStickyNotes_1.1.7.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2890. Event Xml:
  2891. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2892. <System>
  2893. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2894. <EventID>69</EventID>
  2895. <Version>0</Version>
  2896. <Level>2</Level>
  2897. <Task>0</Task>
  2898. <Opcode>0</Opcode>
  2899. <Keywords>0x2000400000000001</Keywords>
  2900. <TimeCreated SystemTime="2016-08-24T00:22:16.846553400Z" />
  2901. <EventRecordID>275</EventRecordID>
  2902. <Correlation ActivityID="{7E5F5F39-FD9A-0004-2174-5F7E9AFDD101}" />
  2903. <Execution ProcessID="3504" ThreadID="8716" />
  2904. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2905. <Computer>DESKTOP-D07KK79</Computer>
  2906. <Security UserID="S-1-5-18" />
  2907. </System>
  2908. <EventData>
  2909. <Data Name="ErrorCode">1168</Data>
  2910. <Data Name="PackageFullName">Microsoft.MicrosoftStickyNotes_1.1.7.0_x64__8wekyb3d8bbwe</Data>
  2911. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2912. <Data Name="DesiredStatus">32</Data>
  2913. <Data Name="CurrentStatus">0</Data>
  2914. </EventData>
  2915. </Event>
  2916.  
  2917. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2918. Source: Microsoft-Windows-AppModel-Runtime
  2919. Date: 8/23/2016 5:22:15 PM
  2920. Event ID: 69
  2921. Task Category: None
  2922. Level: Error
  2923. Keywords: (70368744177664),Process
  2924. User: SYSTEM
  2925. Computer: DESKTOP-D07KK79
  2926. Description:
  2927. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2928. Event Xml:
  2929. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2930. <System>
  2931. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2932. <EventID>69</EventID>
  2933. <Version>0</Version>
  2934. <Level>2</Level>
  2935. <Task>0</Task>
  2936. <Opcode>0</Opcode>
  2937. <Keywords>0x2000400000000001</Keywords>
  2938. <TimeCreated SystemTime="2016-08-24T00:22:15.803420700Z" />
  2939. <EventRecordID>273</EventRecordID>
  2940. <Correlation ActivityID="{7E5F5F39-FD9A-0005-C16B-5F7E9AFDD101}" />
  2941. <Execution ProcessID="3504" ThreadID="8608" />
  2942. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2943. <Computer>DESKTOP-D07KK79</Computer>
  2944. <Security UserID="S-1-5-18" />
  2945. </System>
  2946. <EventData>
  2947. <Data Name="ErrorCode">1168</Data>
  2948. <Data Name="PackageFullName">Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x86__8wekyb3d8bbwe</Data>
  2949. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2950. <Data Name="DesiredStatus">32</Data>
  2951. <Data Name="CurrentStatus">0</Data>
  2952. </EventData>
  2953. </Event>
  2954.  
  2955. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2956. Source: Microsoft-Windows-AppModel-Runtime
  2957. Date: 8/23/2016 5:22:15 PM
  2958. Event ID: 69
  2959. Task Category: None
  2960. Level: Error
  2961. Keywords: (70368744177664),Process
  2962. User: SYSTEM
  2963. Computer: DESKTOP-D07KK79
  2964. Description:
  2965. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  2966. Event Xml:
  2967. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  2968. <System>
  2969. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  2970. <EventID>69</EventID>
  2971. <Version>0</Version>
  2972. <Level>2</Level>
  2973. <Task>0</Task>
  2974. <Opcode>0</Opcode>
  2975. <Keywords>0x2000400000000001</Keywords>
  2976. <TimeCreated SystemTime="2016-08-24T00:22:15.341833000Z" />
  2977. <EventRecordID>271</EventRecordID>
  2978. <Correlation ActivityID="{7E5F5F39-FD9A-0002-2D75-5F7E9AFDD101}" />
  2979. <Execution ProcessID="3504" ThreadID="8716" />
  2980. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  2981. <Computer>DESKTOP-D07KK79</Computer>
  2982. <Security UserID="S-1-5-18" />
  2983. </System>
  2984. <EventData>
  2985. <Data Name="ErrorCode">1168</Data>
  2986. <Data Name="PackageFullName">Microsoft.NET.Native.Runtime.1.4_1.4.24201.0_x64__8wekyb3d8bbwe</Data>
  2987. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  2988. <Data Name="DesiredStatus">32</Data>
  2989. <Data Name="CurrentStatus">0</Data>
  2990. </EventData>
  2991. </Event>
  2992.  
  2993. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  2994. Source: Microsoft-Windows-AppModel-Runtime
  2995. Date: 8/23/2016 5:22:11 PM
  2996. Event ID: 69
  2997. Task Category: None
  2998. Level: Error
  2999. Keywords: (70368744177664),Process
  3000. User: SYSTEM
  3001. Computer: DESKTOP-D07KK79
  3002. Description:
  3003. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3004. Event Xml:
  3005. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3006. <System>
  3007. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3008. <EventID>69</EventID>
  3009. <Version>0</Version>
  3010. <Level>2</Level>
  3011. <Task>0</Task>
  3012. <Opcode>0</Opcode>
  3013. <Keywords>0x2000400000000001</Keywords>
  3014. <TimeCreated SystemTime="2016-08-24T00:22:11.109022300Z" />
  3015. <EventRecordID>266</EventRecordID>
  3016. <Correlation ActivityID="{7E5F5F39-FD9A-0007-A672-5F7E9AFDD101}" />
  3017. <Execution ProcessID="3504" ThreadID="8608" />
  3018. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3019. <Computer>DESKTOP-D07KK79</Computer>
  3020. <Security UserID="S-1-5-18" />
  3021. </System>
  3022. <EventData>
  3023. <Data Name="ErrorCode">1168</Data>
  3024. <Data Name="PackageFullName">Microsoft.Windows.Photos_16.722.10060.0_x64__8wekyb3d8bbwe</Data>
  3025. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3026. <Data Name="DesiredStatus">32</Data>
  3027. <Data Name="CurrentStatus">0</Data>
  3028. </EventData>
  3029. </Event>
  3030.  
  3031. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  3032. Source: Microsoft-Windows-AppModel-Runtime
  3033. Date: 8/23/2016 5:22:07 PM
  3034. Event ID: 69
  3035. Task Category: None
  3036. Level: Error
  3037. Keywords: (70368744177664),Process
  3038. User: SYSTEM
  3039. Computer: DESKTOP-D07KK79
  3040. Description:
  3041. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftSolitaireCollection_3.11.7293.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3042. Event Xml:
  3043. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3044. <System>
  3045. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3046. <EventID>69</EventID>
  3047. <Version>0</Version>
  3048. <Level>2</Level>
  3049. <Task>0</Task>
  3050. <Opcode>0</Opcode>
  3051. <Keywords>0x2000400000000001</Keywords>
  3052. <TimeCreated SystemTime="2016-08-24T00:22:07.428148800Z" />
  3053. <EventRecordID>261</EventRecordID>
  3054. <Correlation ActivityID="{7E5F5F39-FD9A-0006-5170-5F7E9AFDD101}" />
  3055. <Execution ProcessID="3504" ThreadID="8716" />
  3056. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3057. <Computer>DESKTOP-D07KK79</Computer>
  3058. <Security UserID="S-1-5-18" />
  3059. </System>
  3060. <EventData>
  3061. <Data Name="ErrorCode">1168</Data>
  3062. <Data Name="PackageFullName">Microsoft.MicrosoftSolitaireCollection_3.11.7293.0_x64__8wekyb3d8bbwe</Data>
  3063. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3064. <Data Name="DesiredStatus">32</Data>
  3065. <Data Name="CurrentStatus">0</Data>
  3066. </EventData>
  3067. </Event>
  3068.  
  3069. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3070. Source: Microsoft-Windows-DeviceSetupManager
  3071. Date: 8/23/2016 5:21:11 PM
  3072. Event ID: 123
  3073. Task Category: None
  3074. Level: Warning
  3075. Keywords:
  3076. User: SYSTEM
  3077. Computer: DESKTOP-D07KK79
  3078. Description:
  3079. The DSM service was delayed by 13 seconds for a driver query/download/install on device 'ROOT\SYSTEM\0002'
  3080. Event Xml:
  3081. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3082. <System>
  3083. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3084. <EventID>123</EventID>
  3085. <Version>0</Version>
  3086. <Level>3</Level>
  3087. <Task>0</Task>
  3088. <Opcode>0</Opcode>
  3089. <Keywords>0x4000000000000000</Keywords>
  3090. <TimeCreated SystemTime="2016-08-24T00:21:11.084845300Z" />
  3091. <EventRecordID>182</EventRecordID>
  3092. <Correlation />
  3093. <Execution ProcessID="524" ThreadID="2440" />
  3094. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3095. <Computer>DESKTOP-D07KK79</Computer>
  3096. <Security UserID="S-1-5-18" />
  3097. </System>
  3098. <EventData>
  3099. <Data Name="Prop_Seconds">13</Data>
  3100. <Data Name="Prop_DeviceId">ROOT\SYSTEM\0002</Data>
  3101. </EventData>
  3102. </Event>
  3103.  
  3104. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  3105. Source: Microsoft-Windows-AppModel-Runtime
  3106. Date: 8/23/2016 5:20:14 PM
  3107. Event ID: 69
  3108. Task Category: None
  3109. Level: Error
  3110. Keywords: (70368744177664),Process
  3111. User: SYSTEM
  3112. Computer: DESKTOP-D07KK79
  3113. Description:
  3114. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsAlarms_10.1607.1991.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3115. Event Xml:
  3116. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3117. <System>
  3118. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3119. <EventID>69</EventID>
  3120. <Version>0</Version>
  3121. <Level>2</Level>
  3122. <Task>0</Task>
  3123. <Opcode>0</Opcode>
  3124. <Keywords>0x2000400000000001</Keywords>
  3125. <TimeCreated SystemTime="2016-08-24T00:20:14.231544100Z" />
  3126. <EventRecordID>246</EventRecordID>
  3127. <Correlation ActivityID="{7E5F5F39-FD9A-0003-AB69-5F7E9AFDD101}" />
  3128. <Execution ProcessID="3504" ThreadID="8672" />
  3129. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3130. <Computer>DESKTOP-D07KK79</Computer>
  3131. <Security UserID="S-1-5-18" />
  3132. </System>
  3133. <EventData>
  3134. <Data Name="ErrorCode">1168</Data>
  3135. <Data Name="PackageFullName">Microsoft.WindowsAlarms_10.1607.1991.0_x64__8wekyb3d8bbwe</Data>
  3136. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3137. <Data Name="DesiredStatus">32</Data>
  3138. <Data Name="CurrentStatus">0</Data>
  3139. </EventData>
  3140. </Event>
  3141.  
  3142. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  3143. Source: Microsoft-Windows-AppModel-Runtime
  3144. Date: 8/23/2016 5:20:01 PM
  3145. Event ID: 69
  3146. Task Category: None
  3147. Level: Error
  3148. Keywords: (70368744177664),Process
  3149. User: SYSTEM
  3150. Computer: DESKTOP-D07KK79
  3151. Description:
  3152. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsSoundRecorder_10.1607.1891.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3153. Event Xml:
  3154. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3155. <System>
  3156. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3157. <EventID>69</EventID>
  3158. <Version>0</Version>
  3159. <Level>2</Level>
  3160. <Task>0</Task>
  3161. <Opcode>0</Opcode>
  3162. <Keywords>0x2000400000000001</Keywords>
  3163. <TimeCreated SystemTime="2016-08-24T00:20:01.212853500Z" />
  3164. <EventRecordID>243</EventRecordID>
  3165. <Correlation ActivityID="{7E5F5F39-FD9A-0000-C772-5F7E9AFDD101}" />
  3166. <Execution ProcessID="3504" ThreadID="8608" />
  3167. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3168. <Computer>DESKTOP-D07KK79</Computer>
  3169. <Security UserID="S-1-5-18" />
  3170. </System>
  3171. <EventData>
  3172. <Data Name="ErrorCode">1168</Data>
  3173. <Data Name="PackageFullName">Microsoft.WindowsSoundRecorder_10.1607.1891.0_x64__8wekyb3d8bbwe</Data>
  3174. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3175. <Data Name="DesiredStatus">32</Data>
  3176. <Data Name="CurrentStatus">0</Data>
  3177. </EventData>
  3178. </Event>
  3179.  
  3180. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  3181. Source: Microsoft-Windows-AppModel-Runtime
  3182. Date: 8/23/2016 5:19:46 PM
  3183. Event ID: 69
  3184. Task Category: None
  3185. Level: Error
  3186. Keywords: (70368744177664),Process
  3187. User: SYSTEM
  3188. Computer: DESKTOP-D07KK79
  3189. Description:
  3190. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.3DBuilder_11.1.9.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3191. Event Xml:
  3192. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3193. <System>
  3194. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3195. <EventID>69</EventID>
  3196. <Version>0</Version>
  3197. <Level>2</Level>
  3198. <Task>0</Task>
  3199. <Opcode>0</Opcode>
  3200. <Keywords>0x2000400000000001</Keywords>
  3201. <TimeCreated SystemTime="2016-08-24T00:19:46.511732600Z" />
  3202. <EventRecordID>237</EventRecordID>
  3203. <Correlation ActivityID="{7E5F5F39-FD9A-0007-796E-5F7E9AFDD101}" />
  3204. <Execution ProcessID="3504" ThreadID="8672" />
  3205. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3206. <Computer>DESKTOP-D07KK79</Computer>
  3207. <Security UserID="S-1-5-18" />
  3208. </System>
  3209. <EventData>
  3210. <Data Name="ErrorCode">1168</Data>
  3211. <Data Name="PackageFullName">Microsoft.3DBuilder_11.1.9.0_x64__8wekyb3d8bbwe</Data>
  3212. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3213. <Data Name="DesiredStatus">32</Data>
  3214. <Data Name="CurrentStatus">0</Data>
  3215. </EventData>
  3216. </Event>
  3217.  
  3218. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  3219. Source: Microsoft-Windows-AppModel-Runtime
  3220. Date: 8/23/2016 5:19:41 PM
  3221. Event ID: 69
  3222. Task Category: None
  3223. Level: Error
  3224. Keywords: (70368744177664),Process
  3225. User: SYSTEM
  3226. Computer: DESKTOP-D07KK79
  3227. Description:
  3228. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.DesktopAppInstaller_1.0.2181.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  3229. Event Xml:
  3230. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3231. <System>
  3232. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  3233. <EventID>69</EventID>
  3234. <Version>0</Version>
  3235. <Level>2</Level>
  3236. <Task>0</Task>
  3237. <Opcode>0</Opcode>
  3238. <Keywords>0x2000400000000001</Keywords>
  3239. <TimeCreated SystemTime="2016-08-24T00:19:41.994677200Z" />
  3240. <EventRecordID>234</EventRecordID>
  3241. <Correlation ActivityID="{7E5F5F39-FD9A-0007-606E-5F7E9AFDD101}" />
  3242. <Execution ProcessID="3504" ThreadID="8608" />
  3243. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  3244. <Computer>DESKTOP-D07KK79</Computer>
  3245. <Security UserID="S-1-5-18" />
  3246. </System>
  3247. <EventData>
  3248. <Data Name="ErrorCode">1168</Data>
  3249. <Data Name="PackageFullName">Microsoft.DesktopAppInstaller_1.0.2181.0_x64__8wekyb3d8bbwe</Data>
  3250. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  3251. <Data Name="DesiredStatus">32</Data>
  3252. <Data Name="CurrentStatus">0</Data>
  3253. </EventData>
  3254. </Event>
  3255.  
  3256. Log Name: System
  3257. Source: Service Control Manager
  3258. Date: 8/23/2016 5:06:04 PM
  3259. Event ID: 7000
  3260. Task Category: None
  3261. Level: Error
  3262. Keywords: Classic
  3263. User: N/A
  3264. Computer: DESKTOP-D07KK79
  3265. Description:
  3266. The Steam Client Service service failed to start due to the following error:
  3267. The service did not respond to the start or control request in a timely fashion.
  3268. Event Xml:
  3269. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3270. <System>
  3271. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  3272. <EventID Qualifiers="49152">7000</EventID>
  3273. <Version>0</Version>
  3274. <Level>2</Level>
  3275. <Task>0</Task>
  3276. <Opcode>0</Opcode>
  3277. <Keywords>0x8080000000000000</Keywords>
  3278. <TimeCreated SystemTime="2016-08-24T00:06:04.293765800Z" />
  3279. <EventRecordID>786</EventRecordID>
  3280. <Correlation />
  3281. <Execution ProcessID="756" ThreadID="2176" />
  3282. <Channel>System</Channel>
  3283. <Computer>DESKTOP-D07KK79</Computer>
  3284. <Security />
  3285. </System>
  3286. <EventData>
  3287. <Data Name="param1">Steam Client Service</Data>
  3288. <Data Name="param2">%%1053</Data>
  3289. <Binary>53007400650061006D00200043006C00690065006E007400200053006500720076006900630065000000</Binary>
  3290. </EventData>
  3291. </Event>
  3292.  
  3293. Log Name: System
  3294. Source: Service Control Manager
  3295. Date: 8/23/2016 5:06:04 PM
  3296. Event ID: 7009
  3297. Task Category: None
  3298. Level: Error
  3299. Keywords: Classic
  3300. User: N/A
  3301. Computer: DESKTOP-D07KK79
  3302. Description:
  3303. A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
  3304. Event Xml:
  3305. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3306. <System>
  3307. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  3308. <EventID Qualifiers="49152">7009</EventID>
  3309. <Version>0</Version>
  3310. <Level>2</Level>
  3311. <Task>0</Task>
  3312. <Opcode>0</Opcode>
  3313. <Keywords>0x8080000000000000</Keywords>
  3314. <TimeCreated SystemTime="2016-08-24T00:06:04.293765800Z" />
  3315. <EventRecordID>785</EventRecordID>
  3316. <Correlation />
  3317. <Execution ProcessID="756" ThreadID="2176" />
  3318. <Channel>System</Channel>
  3319. <Computer>DESKTOP-D07KK79</Computer>
  3320. <Security />
  3321. </System>
  3322. <EventData>
  3323. <Data Name="param1">30000</Data>
  3324. <Data Name="param2">Steam Client Service</Data>
  3325. <Binary>53007400650061006D00200043006C00690065006E007400200053006500720076006900630065000000</Binary>
  3326. </EventData>
  3327. </Event>
  3328.  
  3329. Log Name: Application
  3330. Source: ESENT
  3331. Date: 8/23/2016 5:05:55 PM
  3332. Event ID: 489
  3333. Task Category: General
  3334. Level: Error
  3335. Keywords: Classic
  3336. User: N/A
  3337. Computer: DESKTOP-D07KK79
  3338. Description:
  3339. firefox (7280) An attempt to open the file "C:\Users\Enzo\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\120712-0049\DBStore\spartan.edb" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
  3340. Event Xml:
  3341. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3342. <System>
  3343. <Provider Name="ESENT" />
  3344. <EventID Qualifiers="0">489</EventID>
  3345. <Level>2</Level>
  3346. <Task>1</Task>
  3347. <Keywords>0x80000000000000</Keywords>
  3348. <TimeCreated SystemTime="2016-08-24T00:05:55.405981300Z" />
  3349. <EventRecordID>546</EventRecordID>
  3350. <Channel>Application</Channel>
  3351. <Computer>DESKTOP-D07KK79</Computer>
  3352. <Security />
  3353. </System>
  3354. <EventData>
  3355. <Data>firefox</Data>
  3356. <Data>7280</Data>
  3357. <Data>
  3358. </Data>
  3359. <Data>C:\Users\Enzo\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\120712-0049\DBStore\spartan.edb</Data>
  3360. <Data>-1032 (0xfffffbf8)</Data>
  3361. <Data>32 (0x00000020)</Data>
  3362. <Data>The process cannot access the file because it is being used by another process. </Data>
  3363. </EventData>
  3364. </Event>
  3365.  
  3366. Log Name: Application
  3367. Source: Application Error
  3368. Date: 8/23/2016 5:04:10 PM
  3369. Event ID: 1000
  3370. Task Category: (100)
  3371. Level: Error
  3372. Keywords: Classic
  3373. User: N/A
  3374. Computer: DESKTOP-D07KK79
  3375. Description:
  3376. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  3377. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  3378. Exception code: 0xc0000604
  3379. Fault offset: 0x0000000000000000
  3380. Faulting process id: 0xbe8
  3381. Faulting application start time: 0x01d1fd9b0a0e2f63
  3382. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  3383. Faulting module path: unknown
  3384. Report Id: e02e97bc-5bc7-4066-9681-8cbd2b2ec500
  3385. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  3386. Faulting package-relative application ID: MicrosoftEdge
  3387. Event Xml:
  3388. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3389. <System>
  3390. <Provider Name="Application Error" />
  3391. <EventID Qualifiers="0">1000</EventID>
  3392. <Level>2</Level>
  3393. <Task>100</Task>
  3394. <Keywords>0x80000000000000</Keywords>
  3395. <TimeCreated SystemTime="2016-08-24T00:04:10.378337600Z" />
  3396. <EventRecordID>544</EventRecordID>
  3397. <Channel>Application</Channel>
  3398. <Computer>DESKTOP-D07KK79</Computer>
  3399. <Security />
  3400. </System>
  3401. <EventData>
  3402. <Data>microsoftedgecp.exe</Data>
  3403. <Data>11.0.14393.82</Data>
  3404. <Data>57a55786</Data>
  3405. <Data>unknown</Data>
  3406. <Data>0.0.0.0</Data>
  3407. <Data>00000000</Data>
  3408. <Data>c0000604</Data>
  3409. <Data>0000000000000000</Data>
  3410. <Data>be8</Data>
  3411. <Data>01d1fd9b0a0e2f63</Data>
  3412. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  3413. <Data>unknown</Data>
  3414. <Data>e02e97bc-5bc7-4066-9681-8cbd2b2ec500</Data>
  3415. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  3416. <Data>MicrosoftEdge</Data>
  3417. </EventData>
  3418. </Event>
  3419.  
  3420. Log Name: System
  3421. Source: Microsoft-Windows-DistributedCOM
  3422. Date: 8/23/2016 5:02:46 PM
  3423. Event ID: 10016
  3424. Task Category: None
  3425. Level: Error
  3426. Keywords: Classic
  3427. User: SYSTEM
  3428. Computer: DESKTOP-D07KK79
  3429. Description:
  3430. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  3431. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  3432. and APPID
  3433. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  3434. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  3435. Event Xml:
  3436. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3437. <System>
  3438. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  3439. <EventID Qualifiers="0">10016</EventID>
  3440. <Version>0</Version>
  3441. <Level>2</Level>
  3442. <Task>0</Task>
  3443. <Opcode>0</Opcode>
  3444. <Keywords>0x8080000000000000</Keywords>
  3445. <TimeCreated SystemTime="2016-08-24T00:02:46.663948100Z" />
  3446. <EventRecordID>782</EventRecordID>
  3447. <Correlation />
  3448. <Execution ProcessID="984" ThreadID="1016" />
  3449. <Channel>System</Channel>
  3450. <Computer>DESKTOP-D07KK79</Computer>
  3451. <Security UserID="S-1-5-18" />
  3452. </System>
  3453. <EventData>
  3454. <Data Name="param1">application-specific</Data>
  3455. <Data Name="param2">Local</Data>
  3456. <Data Name="param3">Activation</Data>
  3457. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  3458. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  3459. <Data Name="param6">NT AUTHORITY</Data>
  3460. <Data Name="param7">SYSTEM</Data>
  3461. <Data Name="param8">S-1-5-18</Data>
  3462. <Data Name="param9">LocalHost (Using LRPC)</Data>
  3463. <Data Name="param10">Unavailable</Data>
  3464. <Data Name="param11">Unavailable</Data>
  3465. </EventData>
  3466. </Event>
  3467.  
  3468. Log Name: Application
  3469. Source: Application Error
  3470. Date: 8/23/2016 5:00:59 PM
  3471. Event ID: 1000
  3472. Task Category: (100)
  3473. Level: Error
  3474. Keywords: Classic
  3475. User: N/A
  3476. Computer: DESKTOP-D07KK79
  3477. Description:
  3478. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  3479. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  3480. Exception code: 0xc0000409
  3481. Fault offset: 0x000d96c2
  3482. Faulting process id: 0x90
  3483. Faulting application start time: 0x01d1fd9a8f7e9cbc
  3484. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  3485. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  3486. Report Id: 1811a4e3-8b29-402b-a6af-0da32a193c4f
  3487. Faulting package full name:
  3488. Faulting package-relative application ID:
  3489. Event Xml:
  3490. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3491. <System>
  3492. <Provider Name="Application Error" />
  3493. <EventID Qualifiers="0">1000</EventID>
  3494. <Level>2</Level>
  3495. <Task>100</Task>
  3496. <Keywords>0x80000000000000</Keywords>
  3497. <TimeCreated SystemTime="2016-08-24T00:00:59.024447400Z" />
  3498. <EventRecordID>529</EventRecordID>
  3499. <Channel>Application</Channel>
  3500. <Computer>DESKTOP-D07KK79</Computer>
  3501. <Security />
  3502. </System>
  3503. <EventData>
  3504. <Data>DipAwayMode.exe</Data>
  3505. <Data>0.0.0.0</Data>
  3506. <Data>00000000</Data>
  3507. <Data>KERNELBASE.dll</Data>
  3508. <Data>10.0.14393.0</Data>
  3509. <Data>57898e34</Data>
  3510. <Data>c0000409</Data>
  3511. <Data>000d96c2</Data>
  3512. <Data>90</Data>
  3513. <Data>01d1fd9a8f7e9cbc</Data>
  3514. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  3515. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  3516. <Data>1811a4e3-8b29-402b-a6af-0da32a193c4f</Data>
  3517. <Data>
  3518. </Data>
  3519. <Data>
  3520. </Data>
  3521. </EventData>
  3522. </Event>
  3523.  
  3524. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3525. Source: Microsoft-Windows-DeviceSetupManager
  3526. Date: 8/23/2016 5:00:29 PM
  3527. Event ID: 201
  3528. Task Category: None
  3529. Level: Warning
  3530. Keywords:
  3531. User: SYSTEM
  3532. Computer: DESKTOP-D07KK79
  3533. Description:
  3534. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  3535. Event Xml:
  3536. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3537. <System>
  3538. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3539. <EventID>201</EventID>
  3540. <Version>0</Version>
  3541. <Level>3</Level>
  3542. <Task>0</Task>
  3543. <Opcode>0</Opcode>
  3544. <Keywords>0x4000000000000000</Keywords>
  3545. <TimeCreated SystemTime="2016-08-24T00:00:29.480823500Z" />
  3546. <EventRecordID>155</EventRecordID>
  3547. <Correlation />
  3548. <Execution ProcessID="524" ThreadID="1720" />
  3549. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3550. <Computer>DESKTOP-D07KK79</Computer>
  3551. <Security UserID="S-1-5-18" />
  3552. </System>
  3553. <EventData>
  3554. </EventData>
  3555. </Event>
  3556.  
  3557. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3558. Source: Microsoft-Windows-DeviceSetupManager
  3559. Date: 8/23/2016 5:00:29 PM
  3560. Event ID: 202
  3561. Task Category: None
  3562. Level: Warning
  3563. Keywords:
  3564. User: SYSTEM
  3565. Computer: DESKTOP-D07KK79
  3566. Description:
  3567. The Network List Manager reports no connectivity to the internet.
  3568. Event Xml:
  3569. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3570. <System>
  3571. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3572. <EventID>202</EventID>
  3573. <Version>0</Version>
  3574. <Level>3</Level>
  3575. <Task>0</Task>
  3576. <Opcode>0</Opcode>
  3577. <Keywords>0x4000000000000000</Keywords>
  3578. <TimeCreated SystemTime="2016-08-24T00:00:29.480735600Z" />
  3579. <EventRecordID>153</EventRecordID>
  3580. <Correlation />
  3581. <Execution ProcessID="524" ThreadID="1720" />
  3582. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3583. <Computer>DESKTOP-D07KK79</Computer>
  3584. <Security UserID="S-1-5-18" />
  3585. </System>
  3586. <EventData>
  3587. </EventData>
  3588. </Event>
  3589.  
  3590. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3591. Source: Microsoft-Windows-DeviceSetupManager
  3592. Date: 8/23/2016 5:00:29 PM
  3593. Event ID: 201
  3594. Task Category: None
  3595. Level: Warning
  3596. Keywords:
  3597. User: SYSTEM
  3598. Computer: DESKTOP-D07KK79
  3599. Description:
  3600. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  3601. Event Xml:
  3602. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3603. <System>
  3604. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3605. <EventID>201</EventID>
  3606. <Version>0</Version>
  3607. <Level>3</Level>
  3608. <Task>0</Task>
  3609. <Opcode>0</Opcode>
  3610. <Keywords>0x4000000000000000</Keywords>
  3611. <TimeCreated SystemTime="2016-08-24T00:00:29.480468900Z" />
  3612. <EventRecordID>152</EventRecordID>
  3613. <Correlation />
  3614. <Execution ProcessID="524" ThreadID="1716" />
  3615. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3616. <Computer>DESKTOP-D07KK79</Computer>
  3617. <Security UserID="S-1-5-18" />
  3618. </System>
  3619. <EventData>
  3620. </EventData>
  3621. </Event>
  3622.  
  3623. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3624. Source: Microsoft-Windows-DeviceSetupManager
  3625. Date: 8/23/2016 5:00:29 PM
  3626. Event ID: 202
  3627. Task Category: None
  3628. Level: Warning
  3629. Keywords:
  3630. User: SYSTEM
  3631. Computer: DESKTOP-D07KK79
  3632. Description:
  3633. The Network List Manager reports no connectivity to the internet.
  3634. Event Xml:
  3635. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3636. <System>
  3637. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3638. <EventID>202</EventID>
  3639. <Version>0</Version>
  3640. <Level>3</Level>
  3641. <Task>0</Task>
  3642. <Opcode>0</Opcode>
  3643. <Keywords>0x4000000000000000</Keywords>
  3644. <TimeCreated SystemTime="2016-08-24T00:00:29.480388200Z" />
  3645. <EventRecordID>151</EventRecordID>
  3646. <Correlation />
  3647. <Execution ProcessID="524" ThreadID="1716" />
  3648. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3649. <Computer>DESKTOP-D07KK79</Computer>
  3650. <Security UserID="S-1-5-18" />
  3651. </System>
  3652. <EventData>
  3653. </EventData>
  3654. </Event>
  3655.  
  3656. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3657. Source: Microsoft-Windows-DeviceSetupManager
  3658. Date: 8/23/2016 5:00:29 PM
  3659. Event ID: 200
  3660. Task Category: None
  3661. Level: Warning
  3662. Keywords:
  3663. User: SYSTEM
  3664. Computer: DESKTOP-D07KK79
  3665. Description:
  3666. A connection to the Windows Update service could not be established.
  3667. Event Xml:
  3668. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3669. <System>
  3670. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3671. <EventID>200</EventID>
  3672. <Version>0</Version>
  3673. <Level>3</Level>
  3674. <Task>0</Task>
  3675. <Opcode>0</Opcode>
  3676. <Keywords>0x4000000000000000</Keywords>
  3677. <TimeCreated SystemTime="2016-08-24T00:00:29.407765200Z" />
  3678. <EventRecordID>150</EventRecordID>
  3679. <Correlation />
  3680. <Execution ProcessID="524" ThreadID="1720" />
  3681. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3682. <Computer>DESKTOP-D07KK79</Computer>
  3683. <Security UserID="S-1-5-18" />
  3684. </System>
  3685. <EventData>
  3686. </EventData>
  3687. </Event>
  3688.  
  3689. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3690. Source: Microsoft-Windows-DeviceSetupManager
  3691. Date: 8/23/2016 5:00:29 PM
  3692. Event ID: 202
  3693. Task Category: None
  3694. Level: Warning
  3695. Keywords:
  3696. User: SYSTEM
  3697. Computer: DESKTOP-D07KK79
  3698. Description:
  3699. The Network List Manager reports no connectivity to the internet.
  3700. Event Xml:
  3701. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3702. <System>
  3703. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3704. <EventID>202</EventID>
  3705. <Version>0</Version>
  3706. <Level>3</Level>
  3707. <Task>0</Task>
  3708. <Opcode>0</Opcode>
  3709. <Keywords>0x4000000000000000</Keywords>
  3710. <TimeCreated SystemTime="2016-08-24T00:00:29.407670600Z" />
  3711. <EventRecordID>149</EventRecordID>
  3712. <Correlation />
  3713. <Execution ProcessID="524" ThreadID="1720" />
  3714. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3715. <Computer>DESKTOP-D07KK79</Computer>
  3716. <Security UserID="S-1-5-18" />
  3717. </System>
  3718. <EventData>
  3719. </EventData>
  3720. </Event>
  3721.  
  3722. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3723. Source: Microsoft-Windows-DeviceSetupManager
  3724. Date: 8/23/2016 5:00:29 PM
  3725. Event ID: 200
  3726. Task Category: None
  3727. Level: Warning
  3728. Keywords:
  3729. User: SYSTEM
  3730. Computer: DESKTOP-D07KK79
  3731. Description:
  3732. A connection to the Windows Update service could not be established.
  3733. Event Xml:
  3734. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3735. <System>
  3736. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3737. <EventID>200</EventID>
  3738. <Version>0</Version>
  3739. <Level>3</Level>
  3740. <Task>0</Task>
  3741. <Opcode>0</Opcode>
  3742. <Keywords>0x4000000000000000</Keywords>
  3743. <TimeCreated SystemTime="2016-08-24T00:00:29.407445100Z" />
  3744. <EventRecordID>148</EventRecordID>
  3745. <Correlation />
  3746. <Execution ProcessID="524" ThreadID="1716" />
  3747. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3748. <Computer>DESKTOP-D07KK79</Computer>
  3749. <Security UserID="S-1-5-18" />
  3750. </System>
  3751. <EventData>
  3752. </EventData>
  3753. </Event>
  3754.  
  3755. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  3756. Source: Microsoft-Windows-DeviceSetupManager
  3757. Date: 8/23/2016 5:00:29 PM
  3758. Event ID: 202
  3759. Task Category: None
  3760. Level: Warning
  3761. Keywords:
  3762. User: SYSTEM
  3763. Computer: DESKTOP-D07KK79
  3764. Description:
  3765. The Network List Manager reports no connectivity to the internet.
  3766. Event Xml:
  3767. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3768. <System>
  3769. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  3770. <EventID>202</EventID>
  3771. <Version>0</Version>
  3772. <Level>3</Level>
  3773. <Task>0</Task>
  3774. <Opcode>0</Opcode>
  3775. <Keywords>0x4000000000000000</Keywords>
  3776. <TimeCreated SystemTime="2016-08-24T00:00:29.407363600Z" />
  3777. <EventRecordID>147</EventRecordID>
  3778. <Correlation />
  3779. <Execution ProcessID="524" ThreadID="1716" />
  3780. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  3781. <Computer>DESKTOP-D07KK79</Computer>
  3782. <Security UserID="S-1-5-18" />
  3783. </System>
  3784. <EventData>
  3785. </EventData>
  3786. </Event>
  3787.  
  3788. Log Name: System
  3789. Source: Microsoft-Windows-Kernel-PnP
  3790. Date: 8/23/2016 5:00:25 PM
  3791. Event ID: 219
  3792. Task Category: (212)
  3793. Level: Warning
  3794. Keywords:
  3795. User: SYSTEM
  3796. Computer: DESKTOP-D07KK79
  3797. Description:
  3798. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  3799. Event Xml:
  3800. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3801. <System>
  3802. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  3803. <EventID>219</EventID>
  3804. <Version>0</Version>
  3805. <Level>3</Level>
  3806. <Task>212</Task>
  3807. <Opcode>0</Opcode>
  3808. <Keywords>0x8000000000000000</Keywords>
  3809. <TimeCreated SystemTime="2016-08-24T00:00:25.586792900Z" />
  3810. <EventRecordID>753</EventRecordID>
  3811. <Correlation />
  3812. <Execution ProcessID="4" ThreadID="260" />
  3813. <Channel>System</Channel>
  3814. <Computer>DESKTOP-D07KK79</Computer>
  3815. <Security UserID="S-1-5-18" />
  3816. </System>
  3817. <EventData>
  3818. <Data Name="DriverNameLength">24</Data>
  3819. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  3820. <Data Name="Status">3221226341</Data>
  3821. <Data Name="FailureNameLength">14</Data>
  3822. <Data Name="FailureName">\Driver\WUDFRd</Data>
  3823. <Data Name="Version">0</Data>
  3824. </EventData>
  3825. </Event>
  3826.  
  3827. Log Name: System
  3828. Source: Microsoft-Windows-DistributedCOM
  3829. Date: 8/23/2016 4:59:44 PM
  3830. Event ID: 10010
  3831. Task Category: None
  3832. Level: Error
  3833. Keywords: Classic
  3834. User: DESKTOP-D07KK79\Enzo
  3835. Computer: DESKTOP-D07KK79
  3836. Description:
  3837. The server {0002DF02-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
  3838. Event Xml:
  3839. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3840. <System>
  3841. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  3842. <EventID Qualifiers="0">10010</EventID>
  3843. <Version>0</Version>
  3844. <Level>2</Level>
  3845. <Task>0</Task>
  3846. <Opcode>0</Opcode>
  3847. <Keywords>0x8080000000000000</Keywords>
  3848. <TimeCreated SystemTime="2016-08-23T23:59:44.211682500Z" />
  3849. <EventRecordID>725</EventRecordID>
  3850. <Correlation />
  3851. <Execution ProcessID="984" ThreadID="1272" />
  3852. <Channel>System</Channel>
  3853. <Computer>DESKTOP-D07KK79</Computer>
  3854. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  3855. </System>
  3856. <EventData>
  3857. <Data Name="param1">{0002DF02-0000-0000-C000-000000000046}</Data>
  3858. </EventData>
  3859. </Event>
  3860.  
  3861. Log Name: Application
  3862. Source: Application Error
  3863. Date: 8/23/2016 4:56:34 PM
  3864. Event ID: 1000
  3865. Task Category: (100)
  3866. Level: Error
  3867. Keywords: Classic
  3868. User: N/A
  3869. Computer: DESKTOP-D07KK79
  3870. Description:
  3871. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  3872. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  3873. Exception code: 0xc0000604
  3874. Fault offset: 0x0000000000000000
  3875. Faulting process id: 0x1388
  3876. Faulting application start time: 0x01d1fd993d2e84a6
  3877. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  3878. Faulting module path: unknown
  3879. Report Id: af7e0c2e-a8f0-43a6-ba23-d6efc26b9cad
  3880. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  3881. Faulting package-relative application ID: MicrosoftEdge
  3882. Event Xml:
  3883. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3884. <System>
  3885. <Provider Name="Application Error" />
  3886. <EventID Qualifiers="0">1000</EventID>
  3887. <Level>2</Level>
  3888. <Task>100</Task>
  3889. <Keywords>0x80000000000000</Keywords>
  3890. <TimeCreated SystemTime="2016-08-23T23:56:34.092901800Z" />
  3891. <EventRecordID>503</EventRecordID>
  3892. <Channel>Application</Channel>
  3893. <Computer>DESKTOP-D07KK79</Computer>
  3894. <Security />
  3895. </System>
  3896. <EventData>
  3897. <Data>microsoftedgecp.exe</Data>
  3898. <Data>11.0.14393.82</Data>
  3899. <Data>57a55786</Data>
  3900. <Data>unknown</Data>
  3901. <Data>0.0.0.0</Data>
  3902. <Data>00000000</Data>
  3903. <Data>c0000604</Data>
  3904. <Data>0000000000000000</Data>
  3905. <Data>1388</Data>
  3906. <Data>01d1fd993d2e84a6</Data>
  3907. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  3908. <Data>unknown</Data>
  3909. <Data>af7e0c2e-a8f0-43a6-ba23-d6efc26b9cad</Data>
  3910. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  3911. <Data>MicrosoftEdge</Data>
  3912. </EventData>
  3913. </Event>
  3914.  
  3915. Log Name: Application
  3916. Source: Application Error
  3917. Date: 8/23/2016 4:56:12 PM
  3918. Event ID: 1000
  3919. Task Category: (100)
  3920. Level: Error
  3921. Keywords: Classic
  3922. User: N/A
  3923. Computer: DESKTOP-D07KK79
  3924. Description:
  3925. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  3926. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  3927. Exception code: 0xc0000604
  3928. Fault offset: 0x0000000000000000
  3929. Faulting process id: 0x15dc
  3930. Faulting application start time: 0x01d1fd993d8f04e0
  3931. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  3932. Faulting module path: unknown
  3933. Report Id: 3c4533c4-87e1-4dbb-a5e5-9f0246def5be
  3934. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  3935. Faulting package-relative application ID: MicrosoftEdge
  3936. Event Xml:
  3937. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3938. <System>
  3939. <Provider Name="Application Error" />
  3940. <EventID Qualifiers="0">1000</EventID>
  3941. <Level>2</Level>
  3942. <Task>100</Task>
  3943. <Keywords>0x80000000000000</Keywords>
  3944. <TimeCreated SystemTime="2016-08-23T23:56:12.559353000Z" />
  3945. <EventRecordID>501</EventRecordID>
  3946. <Channel>Application</Channel>
  3947. <Computer>DESKTOP-D07KK79</Computer>
  3948. <Security />
  3949. </System>
  3950. <EventData>
  3951. <Data>microsoftedgecp.exe</Data>
  3952. <Data>11.0.14393.82</Data>
  3953. <Data>57a55786</Data>
  3954. <Data>unknown</Data>
  3955. <Data>0.0.0.0</Data>
  3956. <Data>00000000</Data>
  3957. <Data>c0000604</Data>
  3958. <Data>0000000000000000</Data>
  3959. <Data>15dc</Data>
  3960. <Data>01d1fd993d8f04e0</Data>
  3961. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  3962. <Data>unknown</Data>
  3963. <Data>3c4533c4-87e1-4dbb-a5e5-9f0246def5be</Data>
  3964. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  3965. <Data>MicrosoftEdge</Data>
  3966. </EventData>
  3967. </Event>
  3968.  
  3969. Log Name: Application
  3970. Source: Application Error
  3971. Date: 8/23/2016 4:56:12 PM
  3972. Event ID: 1000
  3973. Task Category: (100)
  3974. Level: Error
  3975. Keywords: Classic
  3976. User: N/A
  3977. Computer: DESKTOP-D07KK79
  3978. Description:
  3979. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  3980. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  3981. Exception code: 0xc0000604
  3982. Fault offset: 0x0000000000000000
  3983. Faulting process id: 0x15dc
  3984. Faulting application start time: 0x01d1fd993d8f04e0
  3985. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  3986. Faulting module path: unknown
  3987. Report Id: 8c4b3a16-5b74-4351-8e48-8c34d1862fa2
  3988. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  3989. Faulting package-relative application ID: MicrosoftEdge
  3990. Event Xml:
  3991. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  3992. <System>
  3993. <Provider Name="Application Error" />
  3994. <EventID Qualifiers="0">1000</EventID>
  3995. <Level>2</Level>
  3996. <Task>100</Task>
  3997. <Keywords>0x80000000000000</Keywords>
  3998. <TimeCreated SystemTime="2016-08-23T23:56:12.189320500Z" />
  3999. <EventRecordID>499</EventRecordID>
  4000. <Channel>Application</Channel>
  4001. <Computer>DESKTOP-D07KK79</Computer>
  4002. <Security />
  4003. </System>
  4004. <EventData>
  4005. <Data>microsoftedgecp.exe</Data>
  4006. <Data>11.0.14393.82</Data>
  4007. <Data>57a55786</Data>
  4008. <Data>unknown</Data>
  4009. <Data>0.0.0.0</Data>
  4010. <Data>00000000</Data>
  4011. <Data>c0000604</Data>
  4012. <Data>0000000000000000</Data>
  4013. <Data>15dc</Data>
  4014. <Data>01d1fd993d8f04e0</Data>
  4015. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4016. <Data>unknown</Data>
  4017. <Data>8c4b3a16-5b74-4351-8e48-8c34d1862fa2</Data>
  4018. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4019. <Data>MicrosoftEdge</Data>
  4020. </EventData>
  4021. </Event>
  4022.  
  4023. Log Name: Application
  4024. Source: Application Error
  4025. Date: 8/23/2016 4:55:45 PM
  4026. Event ID: 1000
  4027. Task Category: (100)
  4028. Level: Error
  4029. Keywords: Classic
  4030. User: N/A
  4031. Computer: DESKTOP-D07KK79
  4032. Description:
  4033. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  4034. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  4035. Exception code: 0xc0000604
  4036. Fault offset: 0x0000000000000000
  4037. Faulting process id: 0x1388
  4038. Faulting application start time: 0x01d1fd993d2e84a6
  4039. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  4040. Faulting module path: unknown
  4041. Report Id: 30e3cfae-8c65-4ed0-baf7-ea087c129594
  4042. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  4043. Faulting package-relative application ID: MicrosoftEdge
  4044. Event Xml:
  4045. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4046. <System>
  4047. <Provider Name="Application Error" />
  4048. <EventID Qualifiers="0">1000</EventID>
  4049. <Level>2</Level>
  4050. <Task>100</Task>
  4051. <Keywords>0x80000000000000</Keywords>
  4052. <TimeCreated SystemTime="2016-08-23T23:55:45.258943400Z" />
  4053. <EventRecordID>497</EventRecordID>
  4054. <Channel>Application</Channel>
  4055. <Computer>DESKTOP-D07KK79</Computer>
  4056. <Security />
  4057. </System>
  4058. <EventData>
  4059. <Data>microsoftedgecp.exe</Data>
  4060. <Data>11.0.14393.82</Data>
  4061. <Data>57a55786</Data>
  4062. <Data>unknown</Data>
  4063. <Data>0.0.0.0</Data>
  4064. <Data>00000000</Data>
  4065. <Data>c0000604</Data>
  4066. <Data>0000000000000000</Data>
  4067. <Data>1388</Data>
  4068. <Data>01d1fd993d2e84a6</Data>
  4069. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4070. <Data>unknown</Data>
  4071. <Data>30e3cfae-8c65-4ed0-baf7-ea087c129594</Data>
  4072. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4073. <Data>MicrosoftEdge</Data>
  4074. </EventData>
  4075. </Event>
  4076.  
  4077. Log Name: Application
  4078. Source: Application Error
  4079. Date: 8/23/2016 4:55:44 PM
  4080. Event ID: 1000
  4081. Task Category: (100)
  4082. Level: Error
  4083. Keywords: Classic
  4084. User: N/A
  4085. Computer: DESKTOP-D07KK79
  4086. Description:
  4087. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  4088. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  4089. Exception code: 0xc0000604
  4090. Fault offset: 0x0000000000000000
  4091. Faulting process id: 0x1388
  4092. Faulting application start time: 0x01d1fd993d2e84a6
  4093. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  4094. Faulting module path: unknown
  4095. Report Id: a49017d4-daf2-4ddf-a10a-b31fe46c6cb2
  4096. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  4097. Faulting package-relative application ID: MicrosoftEdge
  4098. Event Xml:
  4099. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4100. <System>
  4101. <Provider Name="Application Error" />
  4102. <EventID Qualifiers="0">1000</EventID>
  4103. <Level>2</Level>
  4104. <Task>100</Task>
  4105. <Keywords>0x80000000000000</Keywords>
  4106. <TimeCreated SystemTime="2016-08-23T23:55:44.873909500Z" />
  4107. <EventRecordID>495</EventRecordID>
  4108. <Channel>Application</Channel>
  4109. <Computer>DESKTOP-D07KK79</Computer>
  4110. <Security />
  4111. </System>
  4112. <EventData>
  4113. <Data>microsoftedgecp.exe</Data>
  4114. <Data>11.0.14393.82</Data>
  4115. <Data>57a55786</Data>
  4116. <Data>unknown</Data>
  4117. <Data>0.0.0.0</Data>
  4118. <Data>00000000</Data>
  4119. <Data>c0000604</Data>
  4120. <Data>0000000000000000</Data>
  4121. <Data>1388</Data>
  4122. <Data>01d1fd993d2e84a6</Data>
  4123. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4124. <Data>unknown</Data>
  4125. <Data>a49017d4-daf2-4ddf-a10a-b31fe46c6cb2</Data>
  4126. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4127. <Data>MicrosoftEdge</Data>
  4128. </EventData>
  4129. </Event>
  4130.  
  4131. Log Name: Application
  4132. Source: Application Error
  4133. Date: 8/23/2016 4:55:05 PM
  4134. Event ID: 1000
  4135. Task Category: (100)
  4136. Level: Error
  4137. Keywords: Classic
  4138. User: N/A
  4139. Computer: DESKTOP-D07KK79
  4140. Description:
  4141. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  4142. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  4143. Exception code: 0xc0000604
  4144. Fault offset: 0x0000000000000000
  4145. Faulting process id: 0x15dc
  4146. Faulting application start time: 0x01d1fd993d8f04e0
  4147. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  4148. Faulting module path: unknown
  4149. Report Id: 3a7343ae-6c0a-4107-b57b-e1c416695665
  4150. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  4151. Faulting package-relative application ID: MicrosoftEdge
  4152. Event Xml:
  4153. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4154. <System>
  4155. <Provider Name="Application Error" />
  4156. <EventID Qualifiers="0">1000</EventID>
  4157. <Level>2</Level>
  4158. <Task>100</Task>
  4159. <Keywords>0x80000000000000</Keywords>
  4160. <TimeCreated SystemTime="2016-08-23T23:55:05.400425300Z" />
  4161. <EventRecordID>492</EventRecordID>
  4162. <Channel>Application</Channel>
  4163. <Computer>DESKTOP-D07KK79</Computer>
  4164. <Security />
  4165. </System>
  4166. <EventData>
  4167. <Data>microsoftedgecp.exe</Data>
  4168. <Data>11.0.14393.82</Data>
  4169. <Data>57a55786</Data>
  4170. <Data>unknown</Data>
  4171. <Data>0.0.0.0</Data>
  4172. <Data>00000000</Data>
  4173. <Data>c0000604</Data>
  4174. <Data>0000000000000000</Data>
  4175. <Data>15dc</Data>
  4176. <Data>01d1fd993d8f04e0</Data>
  4177. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4178. <Data>unknown</Data>
  4179. <Data>3a7343ae-6c0a-4107-b57b-e1c416695665</Data>
  4180. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4181. <Data>MicrosoftEdge</Data>
  4182. </EventData>
  4183. </Event>
  4184.  
  4185. Log Name: Application
  4186. Source: Application Error
  4187. Date: 8/23/2016 4:55:04 PM
  4188. Event ID: 1000
  4189. Task Category: (100)
  4190. Level: Error
  4191. Keywords: Classic
  4192. User: N/A
  4193. Computer: DESKTOP-D07KK79
  4194. Description:
  4195. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  4196. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  4197. Exception code: 0xc0000604
  4198. Fault offset: 0x0000000000000000
  4199. Faulting process id: 0x15dc
  4200. Faulting application start time: 0x01d1fd993d8f04e0
  4201. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  4202. Faulting module path: unknown
  4203. Report Id: efec5edc-b1ad-4239-84e3-c24ffa043302
  4204. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  4205. Faulting package-relative application ID: MicrosoftEdge
  4206. Event Xml:
  4207. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4208. <System>
  4209. <Provider Name="Application Error" />
  4210. <EventID Qualifiers="0">1000</EventID>
  4211. <Level>2</Level>
  4212. <Task>100</Task>
  4213. <Keywords>0x80000000000000</Keywords>
  4214. <TimeCreated SystemTime="2016-08-23T23:55:04.484344200Z" />
  4215. <EventRecordID>490</EventRecordID>
  4216. <Channel>Application</Channel>
  4217. <Computer>DESKTOP-D07KK79</Computer>
  4218. <Security />
  4219. </System>
  4220. <EventData>
  4221. <Data>microsoftedgecp.exe</Data>
  4222. <Data>11.0.14393.82</Data>
  4223. <Data>57a55786</Data>
  4224. <Data>unknown</Data>
  4225. <Data>0.0.0.0</Data>
  4226. <Data>00000000</Data>
  4227. <Data>c0000604</Data>
  4228. <Data>0000000000000000</Data>
  4229. <Data>15dc</Data>
  4230. <Data>01d1fd993d8f04e0</Data>
  4231. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4232. <Data>unknown</Data>
  4233. <Data>efec5edc-b1ad-4239-84e3-c24ffa043302</Data>
  4234. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4235. <Data>MicrosoftEdge</Data>
  4236. </EventData>
  4237. </Event>
  4238.  
  4239. Log Name: Application
  4240. Source: Application Error
  4241. Date: 8/23/2016 4:54:36 PM
  4242. Event ID: 1000
  4243. Task Category: (100)
  4244. Level: Error
  4245. Keywords: Classic
  4246. User: N/A
  4247. Computer: DESKTOP-D07KK79
  4248. Description:
  4249. Faulting application name: microsoftedgecp.exe, version: 11.0.14393.82, time stamp: 0x57a55786
  4250. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  4251. Exception code: 0xc0000604
  4252. Fault offset: 0x0000000000000000
  4253. Faulting process id: 0x15dc
  4254. Faulting application start time: 0x01d1fd993d8f04e0
  4255. Faulting application path: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe
  4256. Faulting module path: unknown
  4257. Report Id: 4f876d3c-b234-46ae-9eab-5d72051d23c3
  4258. Faulting package full name: Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe
  4259. Faulting package-relative application ID: MicrosoftEdge
  4260. Event Xml:
  4261. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4262. <System>
  4263. <Provider Name="Application Error" />
  4264. <EventID Qualifiers="0">1000</EventID>
  4265. <Level>2</Level>
  4266. <Task>100</Task>
  4267. <Keywords>0x80000000000000</Keywords>
  4268. <TimeCreated SystemTime="2016-08-23T23:54:36.285333500Z" />
  4269. <EventRecordID>482</EventRecordID>
  4270. <Channel>Application</Channel>
  4271. <Computer>DESKTOP-D07KK79</Computer>
  4272. <Security />
  4273. </System>
  4274. <EventData>
  4275. <Data>microsoftedgecp.exe</Data>
  4276. <Data>11.0.14393.82</Data>
  4277. <Data>57a55786</Data>
  4278. <Data>unknown</Data>
  4279. <Data>0.0.0.0</Data>
  4280. <Data>00000000</Data>
  4281. <Data>c0000604</Data>
  4282. <Data>0000000000000000</Data>
  4283. <Data>15dc</Data>
  4284. <Data>01d1fd993d8f04e0</Data>
  4285. <Data>C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe</Data>
  4286. <Data>unknown</Data>
  4287. <Data>4f876d3c-b234-46ae-9eab-5d72051d23c3</Data>
  4288. <Data>Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4289. <Data>MicrosoftEdge</Data>
  4290. </EventData>
  4291. </Event>
  4292.  
  4293. Log Name: System
  4294. Source: Service Control Manager
  4295. Date: 8/23/2016 4:54:26 PM
  4296. Event ID: 7030
  4297. Task Category: None
  4298. Level: Error
  4299. Keywords: Classic
  4300. User: N/A
  4301. Computer: DESKTOP-D07KK79
  4302. Description:
  4303. The ASGT service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
  4304. Event Xml:
  4305. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4306. <System>
  4307. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  4308. <EventID Qualifiers="49152">7030</EventID>
  4309. <Version>0</Version>
  4310. <Level>2</Level>
  4311. <Task>0</Task>
  4312. <Opcode>0</Opcode>
  4313. <Keywords>0x8080000000000000</Keywords>
  4314. <TimeCreated SystemTime="2016-08-23T23:54:26.426463300Z" />
  4315. <EventRecordID>724</EventRecordID>
  4316. <Correlation />
  4317. <Execution ProcessID="756" ThreadID="2300" />
  4318. <Channel>System</Channel>
  4319. <Computer>DESKTOP-D07KK79</Computer>
  4320. <Security />
  4321. </System>
  4322. <EventData>
  4323. <Data Name="param1">ASGT</Data>
  4324. </EventData>
  4325. </Event>
  4326.  
  4327. Log Name: System
  4328. Source: Microsoft-Windows-DistributedCOM
  4329. Date: 8/23/2016 4:54:20 PM
  4330. Event ID: 10001
  4331. Task Category: None
  4332. Level: Error
  4333. Keywords: Classic
  4334. User: DESKTOP-D07KK79\Enzo
  4335. Computer: DESKTOP-D07KK79
  4336. Description:
  4337. Unable to start a DCOM Server: {B3EDE298-AE75-4A1C-AB7E-1B9229B77BBE} as Unavailable/Unavailable. The error:
  4338. "740"
  4339. Happened while starting this command:
  4340. C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe -Embedding
  4341. Event Xml:
  4342. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4343. <System>
  4344. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  4345. <EventID Qualifiers="0">10001</EventID>
  4346. <Version>0</Version>
  4347. <Level>2</Level>
  4348. <Task>0</Task>
  4349. <Opcode>0</Opcode>
  4350. <Keywords>0x8080000000000000</Keywords>
  4351. <TimeCreated SystemTime="2016-08-23T23:54:20.910976200Z" />
  4352. <EventRecordID>722</EventRecordID>
  4353. <Correlation />
  4354. <Execution ProcessID="864" ThreadID="4168" />
  4355. <Channel>System</Channel>
  4356. <Computer>DESKTOP-D07KK79</Computer>
  4357. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  4358. </System>
  4359. <EventData>
  4360. <Data Name="param1">C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe -Embedding</Data>
  4361. <Data Name="param2">740</Data>
  4362. <Data Name="param3">{B3EDE298-AE75-4A1C-AB7E-1B9229B77BBE}</Data>
  4363. <Data Name="param4">Unavailable</Data>
  4364. <Data Name="param5">Unavailable</Data>
  4365. </EventData>
  4366. </Event>
  4367.  
  4368. Log Name: System
  4369. Source: Microsoft-Windows-DistributedCOM
  4370. Date: 8/23/2016 4:51:16 PM
  4371. Event ID: 10016
  4372. Task Category: None
  4373. Level: Error
  4374. Keywords: Classic
  4375. User: DESKTOP-D07KK79\Enzo
  4376. Computer: DESKTOP-D07KK79
  4377. Description:
  4378. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  4379. {9E175B6D-F52A-11D8-B9A5-505054503030}
  4380. and APPID
  4381. {9E175B9C-F52A-11D8-B9A5-505054503030}
  4382. to the user DESKTOP-D07KK79\Enzo SID (S-1-5-21-1999763852-2568256858-2669145966-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe SID (S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194). This security permission can be modified using the Component Services administrative tool.
  4383. Event Xml:
  4384. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4385. <System>
  4386. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  4387. <EventID Qualifiers="0">10016</EventID>
  4388. <Version>0</Version>
  4389. <Level>2</Level>
  4390. <Task>0</Task>
  4391. <Opcode>0</Opcode>
  4392. <Keywords>0x8080000000000000</Keywords>
  4393. <TimeCreated SystemTime="2016-08-23T23:51:16.675223100Z" />
  4394. <EventRecordID>706</EventRecordID>
  4395. <Correlation />
  4396. <Execution ProcessID="984" ThreadID="5008" />
  4397. <Channel>System</Channel>
  4398. <Computer>DESKTOP-D07KK79</Computer>
  4399. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  4400. </System>
  4401. <EventData>
  4402. <Data Name="param1">application-specific</Data>
  4403. <Data Name="param2">Local</Data>
  4404. <Data Name="param3">Activation</Data>
  4405. <Data Name="param4">{9E175B6D-F52A-11D8-B9A5-505054503030}</Data>
  4406. <Data Name="param5">{9E175B9C-F52A-11D8-B9A5-505054503030}</Data>
  4407. <Data Name="param6">DESKTOP-D07KK79</Data>
  4408. <Data Name="param7">Enzo</Data>
  4409. <Data Name="param8">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  4410. <Data Name="param9">LocalHost (Using LRPC)</Data>
  4411. <Data Name="param10">Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  4412. <Data Name="param11">S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194</Data>
  4413. </EventData>
  4414. </Event>
  4415.  
  4416. Log Name: Application
  4417. Source: Application Error
  4418. Date: 8/23/2016 4:47:20 PM
  4419. Event ID: 1000
  4420. Task Category: (100)
  4421. Level: Error
  4422. Keywords: Classic
  4423. User: N/A
  4424. Computer: DESKTOP-D07KK79
  4425. Description:
  4426. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  4427. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  4428. Exception code: 0xc0000409
  4429. Fault offset: 0x000d96c2
  4430. Faulting process id: 0xf94
  4431. Faulting application start time: 0x01d1fd98a3b89666
  4432. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  4433. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  4434. Report Id: 2e830251-6268-4fb2-8168-f91f9216b1f7
  4435. Faulting package full name:
  4436. Faulting package-relative application ID:
  4437. Event Xml:
  4438. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4439. <System>
  4440. <Provider Name="Application Error" />
  4441. <EventID Qualifiers="0">1000</EventID>
  4442. <Level>2</Level>
  4443. <Task>100</Task>
  4444. <Keywords>0x80000000000000</Keywords>
  4445. <TimeCreated SystemTime="2016-08-23T23:47:20.586702900Z" />
  4446. <EventRecordID>414</EventRecordID>
  4447. <Channel>Application</Channel>
  4448. <Computer>DESKTOP-D07KK79</Computer>
  4449. <Security />
  4450. </System>
  4451. <EventData>
  4452. <Data>DipAwayMode.exe</Data>
  4453. <Data>0.0.0.0</Data>
  4454. <Data>00000000</Data>
  4455. <Data>KERNELBASE.dll</Data>
  4456. <Data>10.0.14393.0</Data>
  4457. <Data>57898e34</Data>
  4458. <Data>c0000409</Data>
  4459. <Data>000d96c2</Data>
  4460. <Data>f94</Data>
  4461. <Data>01d1fd98a3b89666</Data>
  4462. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  4463. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  4464. <Data>2e830251-6268-4fb2-8168-f91f9216b1f7</Data>
  4465. <Data>
  4466. </Data>
  4467. <Data>
  4468. </Data>
  4469. </EventData>
  4470. </Event>
  4471.  
  4472. Log Name: System
  4473. Source: Microsoft-Windows-DistributedCOM
  4474. Date: 8/23/2016 4:46:59 PM
  4475. Event ID: 10016
  4476. Task Category: None
  4477. Level: Error
  4478. Keywords: Classic
  4479. User: SYSTEM
  4480. Computer: DESKTOP-D07KK79
  4481. Description:
  4482. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  4483. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  4484. and APPID
  4485. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  4486. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  4487. Event Xml:
  4488. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4489. <System>
  4490. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  4491. <EventID Qualifiers="0">10016</EventID>
  4492. <Version>0</Version>
  4493. <Level>2</Level>
  4494. <Task>0</Task>
  4495. <Opcode>0</Opcode>
  4496. <Keywords>0x8080000000000000</Keywords>
  4497. <TimeCreated SystemTime="2016-08-23T23:46:59.380831200Z" />
  4498. <EventRecordID>704</EventRecordID>
  4499. <Correlation />
  4500. <Execution ProcessID="984" ThreadID="1268" />
  4501. <Channel>System</Channel>
  4502. <Computer>DESKTOP-D07KK79</Computer>
  4503. <Security UserID="S-1-5-18" />
  4504. </System>
  4505. <EventData>
  4506. <Data Name="param1">application-specific</Data>
  4507. <Data Name="param2">Local</Data>
  4508. <Data Name="param3">Activation</Data>
  4509. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  4510. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  4511. <Data Name="param6">NT AUTHORITY</Data>
  4512. <Data Name="param7">SYSTEM</Data>
  4513. <Data Name="param8">S-1-5-18</Data>
  4514. <Data Name="param9">LocalHost (Using LRPC)</Data>
  4515. <Data Name="param10">Unavailable</Data>
  4516. <Data Name="param11">Unavailable</Data>
  4517. </EventData>
  4518. </Event>
  4519.  
  4520. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4521. Source: Microsoft-Windows-DeviceSetupManager
  4522. Date: 8/23/2016 4:46:49 PM
  4523. Event ID: 201
  4524. Task Category: None
  4525. Level: Warning
  4526. Keywords:
  4527. User: SYSTEM
  4528. Computer: DESKTOP-D07KK79
  4529. Description:
  4530. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  4531. Event Xml:
  4532. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4533. <System>
  4534. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4535. <EventID>201</EventID>
  4536. <Version>0</Version>
  4537. <Level>3</Level>
  4538. <Task>0</Task>
  4539. <Opcode>0</Opcode>
  4540. <Keywords>0x4000000000000000</Keywords>
  4541. <TimeCreated SystemTime="2016-08-23T23:46:49.786792000Z" />
  4542. <EventRecordID>129</EventRecordID>
  4543. <Correlation />
  4544. <Execution ProcessID="512" ThreadID="1684" />
  4545. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4546. <Computer>DESKTOP-D07KK79</Computer>
  4547. <Security UserID="S-1-5-18" />
  4548. </System>
  4549. <EventData>
  4550. </EventData>
  4551. </Event>
  4552.  
  4553. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4554. Source: Microsoft-Windows-DeviceSetupManager
  4555. Date: 8/23/2016 4:46:49 PM
  4556. Event ID: 202
  4557. Task Category: None
  4558. Level: Warning
  4559. Keywords:
  4560. User: SYSTEM
  4561. Computer: DESKTOP-D07KK79
  4562. Description:
  4563. The Network List Manager reports no connectivity to the internet.
  4564. Event Xml:
  4565. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4566. <System>
  4567. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4568. <EventID>202</EventID>
  4569. <Version>0</Version>
  4570. <Level>3</Level>
  4571. <Task>0</Task>
  4572. <Opcode>0</Opcode>
  4573. <Keywords>0x4000000000000000</Keywords>
  4574. <TimeCreated SystemTime="2016-08-23T23:46:49.786719800Z" />
  4575. <EventRecordID>128</EventRecordID>
  4576. <Correlation />
  4577. <Execution ProcessID="512" ThreadID="1684" />
  4578. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4579. <Computer>DESKTOP-D07KK79</Computer>
  4580. <Security UserID="S-1-5-18" />
  4581. </System>
  4582. <EventData>
  4583. </EventData>
  4584. </Event>
  4585.  
  4586. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4587. Source: Microsoft-Windows-DeviceSetupManager
  4588. Date: 8/23/2016 4:46:49 PM
  4589. Event ID: 201
  4590. Task Category: None
  4591. Level: Warning
  4592. Keywords:
  4593. User: SYSTEM
  4594. Computer: DESKTOP-D07KK79
  4595. Description:
  4596. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  4597. Event Xml:
  4598. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4599. <System>
  4600. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4601. <EventID>201</EventID>
  4602. <Version>0</Version>
  4603. <Level>3</Level>
  4604. <Task>0</Task>
  4605. <Opcode>0</Opcode>
  4606. <Keywords>0x4000000000000000</Keywords>
  4607. <TimeCreated SystemTime="2016-08-23T23:46:49.786598800Z" />
  4608. <EventRecordID>127</EventRecordID>
  4609. <Correlation />
  4610. <Execution ProcessID="512" ThreadID="1700" />
  4611. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4612. <Computer>DESKTOP-D07KK79</Computer>
  4613. <Security UserID="S-1-5-18" />
  4614. </System>
  4615. <EventData>
  4616. </EventData>
  4617. </Event>
  4618.  
  4619. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4620. Source: Microsoft-Windows-DeviceSetupManager
  4621. Date: 8/23/2016 4:46:49 PM
  4622. Event ID: 202
  4623. Task Category: None
  4624. Level: Warning
  4625. Keywords:
  4626. User: SYSTEM
  4627. Computer: DESKTOP-D07KK79
  4628. Description:
  4629. The Network List Manager reports no connectivity to the internet.
  4630. Event Xml:
  4631. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4632. <System>
  4633. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4634. <EventID>202</EventID>
  4635. <Version>0</Version>
  4636. <Level>3</Level>
  4637. <Task>0</Task>
  4638. <Opcode>0</Opcode>
  4639. <Keywords>0x4000000000000000</Keywords>
  4640. <TimeCreated SystemTime="2016-08-23T23:46:49.786534500Z" />
  4641. <EventRecordID>126</EventRecordID>
  4642. <Correlation />
  4643. <Execution ProcessID="512" ThreadID="1700" />
  4644. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4645. <Computer>DESKTOP-D07KK79</Computer>
  4646. <Security UserID="S-1-5-18" />
  4647. </System>
  4648. <EventData>
  4649. </EventData>
  4650. </Event>
  4651.  
  4652. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4653. Source: Microsoft-Windows-DeviceSetupManager
  4654. Date: 8/23/2016 4:46:49 PM
  4655. Event ID: 200
  4656. Task Category: None
  4657. Level: Warning
  4658. Keywords:
  4659. User: SYSTEM
  4660. Computer: DESKTOP-D07KK79
  4661. Description:
  4662. A connection to the Windows Update service could not be established.
  4663. Event Xml:
  4664. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4665. <System>
  4666. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4667. <EventID>200</EventID>
  4668. <Version>0</Version>
  4669. <Level>3</Level>
  4670. <Task>0</Task>
  4671. <Opcode>0</Opcode>
  4672. <Keywords>0x4000000000000000</Keywords>
  4673. <TimeCreated SystemTime="2016-08-23T23:46:49.498133100Z" />
  4674. <EventRecordID>125</EventRecordID>
  4675. <Correlation />
  4676. <Execution ProcessID="512" ThreadID="1692" />
  4677. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4678. <Computer>DESKTOP-D07KK79</Computer>
  4679. <Security UserID="S-1-5-18" />
  4680. </System>
  4681. <EventData>
  4682. </EventData>
  4683. </Event>
  4684.  
  4685. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4686. Source: Microsoft-Windows-DeviceSetupManager
  4687. Date: 8/23/2016 4:46:49 PM
  4688. Event ID: 202
  4689. Task Category: None
  4690. Level: Warning
  4691. Keywords:
  4692. User: SYSTEM
  4693. Computer: DESKTOP-D07KK79
  4694. Description:
  4695. The Network List Manager reports no connectivity to the internet.
  4696. Event Xml:
  4697. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4698. <System>
  4699. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4700. <EventID>202</EventID>
  4701. <Version>0</Version>
  4702. <Level>3</Level>
  4703. <Task>0</Task>
  4704. <Opcode>0</Opcode>
  4705. <Keywords>0x4000000000000000</Keywords>
  4706. <TimeCreated SystemTime="2016-08-23T23:46:49.498035300Z" />
  4707. <EventRecordID>124</EventRecordID>
  4708. <Correlation />
  4709. <Execution ProcessID="512" ThreadID="1692" />
  4710. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4711. <Computer>DESKTOP-D07KK79</Computer>
  4712. <Security UserID="S-1-5-18" />
  4713. </System>
  4714. <EventData>
  4715. </EventData>
  4716. </Event>
  4717.  
  4718. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4719. Source: Microsoft-Windows-DeviceSetupManager
  4720. Date: 8/23/2016 4:46:49 PM
  4721. Event ID: 200
  4722. Task Category: None
  4723. Level: Warning
  4724. Keywords:
  4725. User: SYSTEM
  4726. Computer: DESKTOP-D07KK79
  4727. Description:
  4728. A connection to the Windows Update service could not be established.
  4729. Event Xml:
  4730. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4731. <System>
  4732. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4733. <EventID>200</EventID>
  4734. <Version>0</Version>
  4735. <Level>3</Level>
  4736. <Task>0</Task>
  4737. <Opcode>0</Opcode>
  4738. <Keywords>0x4000000000000000</Keywords>
  4739. <TimeCreated SystemTime="2016-08-23T23:46:49.496335800Z" />
  4740. <EventRecordID>123</EventRecordID>
  4741. <Correlation />
  4742. <Execution ProcessID="512" ThreadID="1684" />
  4743. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4744. <Computer>DESKTOP-D07KK79</Computer>
  4745. <Security UserID="S-1-5-18" />
  4746. </System>
  4747. <EventData>
  4748. </EventData>
  4749. </Event>
  4750.  
  4751. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4752. Source: Microsoft-Windows-DeviceSetupManager
  4753. Date: 8/23/2016 4:46:49 PM
  4754. Event ID: 202
  4755. Task Category: None
  4756. Level: Warning
  4757. Keywords:
  4758. User: SYSTEM
  4759. Computer: DESKTOP-D07KK79
  4760. Description:
  4761. The Network List Manager reports no connectivity to the internet.
  4762. Event Xml:
  4763. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4764. <System>
  4765. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4766. <EventID>202</EventID>
  4767. <Version>0</Version>
  4768. <Level>3</Level>
  4769. <Task>0</Task>
  4770. <Opcode>0</Opcode>
  4771. <Keywords>0x4000000000000000</Keywords>
  4772. <TimeCreated SystemTime="2016-08-23T23:46:49.496229800Z" />
  4773. <EventRecordID>122</EventRecordID>
  4774. <Correlation />
  4775. <Execution ProcessID="512" ThreadID="1684" />
  4776. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4777. <Computer>DESKTOP-D07KK79</Computer>
  4778. <Security UserID="S-1-5-18" />
  4779. </System>
  4780. <EventData>
  4781. </EventData>
  4782. </Event>
  4783.  
  4784. Log Name: System
  4785. Source: Microsoft-Windows-Kernel-PnP
  4786. Date: 8/23/2016 4:46:46 PM
  4787. Event ID: 219
  4788. Task Category: (212)
  4789. Level: Warning
  4790. Keywords:
  4791. User: SYSTEM
  4792. Computer: DESKTOP-D07KK79
  4793. Description:
  4794. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  4795. Event Xml:
  4796. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4797. <System>
  4798. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  4799. <EventID>219</EventID>
  4800. <Version>0</Version>
  4801. <Level>3</Level>
  4802. <Task>212</Task>
  4803. <Opcode>0</Opcode>
  4804. <Keywords>0x8000000000000000</Keywords>
  4805. <TimeCreated SystemTime="2016-08-23T23:46:46.308410100Z" />
  4806. <EventRecordID>679</EventRecordID>
  4807. <Correlation />
  4808. <Execution ProcessID="4" ThreadID="400" />
  4809. <Channel>System</Channel>
  4810. <Computer>DESKTOP-D07KK79</Computer>
  4811. <Security UserID="S-1-5-18" />
  4812. </System>
  4813. <EventData>
  4814. <Data Name="DriverNameLength">24</Data>
  4815. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  4816. <Data Name="Status">3221226341</Data>
  4817. <Data Name="FailureNameLength">14</Data>
  4818. <Data Name="FailureName">\Driver\WUDFRd</Data>
  4819. <Data Name="Version">0</Data>
  4820. </EventData>
  4821. </Event>
  4822.  
  4823. Log Name: Application
  4824. Source: Application Error
  4825. Date: 8/23/2016 4:45:49 PM
  4826. Event ID: 1000
  4827. Task Category: (100)
  4828. Level: Error
  4829. Keywords: Classic
  4830. User: N/A
  4831. Computer: DESKTOP-D07KK79
  4832. Description:
  4833. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  4834. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  4835. Exception code: 0xc0000409
  4836. Fault offset: 0x000d96c2
  4837. Faulting process id: 0xf78
  4838. Faulting application start time: 0x01d1fd98705a0e49
  4839. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  4840. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  4841. Report Id: c5bdc911-ba17-407b-b89b-fad52de32e80
  4842. Faulting package full name:
  4843. Faulting package-relative application ID:
  4844. Event Xml:
  4845. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4846. <System>
  4847. <Provider Name="Application Error" />
  4848. <EventID Qualifiers="0">1000</EventID>
  4849. <Level>2</Level>
  4850. <Task>100</Task>
  4851. <Keywords>0x80000000000000</Keywords>
  4852. <TimeCreated SystemTime="2016-08-23T23:45:49.894752900Z" />
  4853. <EventRecordID>393</EventRecordID>
  4854. <Channel>Application</Channel>
  4855. <Computer>DESKTOP-D07KK79</Computer>
  4856. <Security />
  4857. </System>
  4858. <EventData>
  4859. <Data>DipAwayMode.exe</Data>
  4860. <Data>0.0.0.0</Data>
  4861. <Data>00000000</Data>
  4862. <Data>KERNELBASE.dll</Data>
  4863. <Data>10.0.14393.0</Data>
  4864. <Data>57898e34</Data>
  4865. <Data>c0000409</Data>
  4866. <Data>000d96c2</Data>
  4867. <Data>f78</Data>
  4868. <Data>01d1fd98705a0e49</Data>
  4869. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  4870. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  4871. <Data>c5bdc911-ba17-407b-b89b-fad52de32e80</Data>
  4872. <Data>
  4873. </Data>
  4874. <Data>
  4875. </Data>
  4876. </EventData>
  4877. </Event>
  4878.  
  4879. Log Name: System
  4880. Source: Microsoft-Windows-DistributedCOM
  4881. Date: 8/23/2016 4:45:33 PM
  4882. Event ID: 10016
  4883. Task Category: None
  4884. Level: Error
  4885. Keywords: Classic
  4886. User: SYSTEM
  4887. Computer: DESKTOP-D07KK79
  4888. Description:
  4889. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  4890. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  4891. and APPID
  4892. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  4893. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  4894. Event Xml:
  4895. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4896. <System>
  4897. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  4898. <EventID Qualifiers="0">10016</EventID>
  4899. <Version>0</Version>
  4900. <Level>2</Level>
  4901. <Task>0</Task>
  4902. <Opcode>0</Opcode>
  4903. <Keywords>0x8080000000000000</Keywords>
  4904. <TimeCreated SystemTime="2016-08-23T23:45:33.247280400Z" />
  4905. <EventRecordID>651</EventRecordID>
  4906. <Correlation />
  4907. <Execution ProcessID="988" ThreadID="1020" />
  4908. <Channel>System</Channel>
  4909. <Computer>DESKTOP-D07KK79</Computer>
  4910. <Security UserID="S-1-5-18" />
  4911. </System>
  4912. <EventData>
  4913. <Data Name="param1">application-specific</Data>
  4914. <Data Name="param2">Local</Data>
  4915. <Data Name="param3">Activation</Data>
  4916. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  4917. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  4918. <Data Name="param6">NT AUTHORITY</Data>
  4919. <Data Name="param7">SYSTEM</Data>
  4920. <Data Name="param8">S-1-5-18</Data>
  4921. <Data Name="param9">LocalHost (Using LRPC)</Data>
  4922. <Data Name="param10">Unavailable</Data>
  4923. <Data Name="param11">Unavailable</Data>
  4924. </EventData>
  4925. </Event>
  4926.  
  4927. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4928. Source: Microsoft-Windows-DeviceSetupManager
  4929. Date: 8/23/2016 4:45:23 PM
  4930. Event ID: 201
  4931. Task Category: None
  4932. Level: Warning
  4933. Keywords:
  4934. User: SYSTEM
  4935. Computer: DESKTOP-D07KK79
  4936. Description:
  4937. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  4938. Event Xml:
  4939. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4940. <System>
  4941. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4942. <EventID>201</EventID>
  4943. <Version>0</Version>
  4944. <Level>3</Level>
  4945. <Task>0</Task>
  4946. <Opcode>0</Opcode>
  4947. <Keywords>0x4000000000000000</Keywords>
  4948. <TimeCreated SystemTime="2016-08-23T23:45:23.822890100Z" />
  4949. <EventRecordID>113</EventRecordID>
  4950. <Correlation />
  4951. <Execution ProcessID="512" ThreadID="1684" />
  4952. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4953. <Computer>DESKTOP-D07KK79</Computer>
  4954. <Security UserID="S-1-5-18" />
  4955. </System>
  4956. <EventData>
  4957. </EventData>
  4958. </Event>
  4959.  
  4960. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4961. Source: Microsoft-Windows-DeviceSetupManager
  4962. Date: 8/23/2016 4:45:23 PM
  4963. Event ID: 202
  4964. Task Category: None
  4965. Level: Warning
  4966. Keywords:
  4967. User: SYSTEM
  4968. Computer: DESKTOP-D07KK79
  4969. Description:
  4970. The Network List Manager reports no connectivity to the internet.
  4971. Event Xml:
  4972. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  4973. <System>
  4974. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  4975. <EventID>202</EventID>
  4976. <Version>0</Version>
  4977. <Level>3</Level>
  4978. <Task>0</Task>
  4979. <Opcode>0</Opcode>
  4980. <Keywords>0x4000000000000000</Keywords>
  4981. <TimeCreated SystemTime="2016-08-23T23:45:23.822805100Z" />
  4982. <EventRecordID>112</EventRecordID>
  4983. <Correlation />
  4984. <Execution ProcessID="512" ThreadID="1684" />
  4985. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  4986. <Computer>DESKTOP-D07KK79</Computer>
  4987. <Security UserID="S-1-5-18" />
  4988. </System>
  4989. <EventData>
  4990. </EventData>
  4991. </Event>
  4992.  
  4993. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  4994. Source: Microsoft-Windows-DeviceSetupManager
  4995. Date: 8/23/2016 4:45:23 PM
  4996. Event ID: 201
  4997. Task Category: None
  4998. Level: Warning
  4999. Keywords:
  5000. User: SYSTEM
  5001. Computer: DESKTOP-D07KK79
  5002. Description:
  5003. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  5004. Event Xml:
  5005. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5006. <System>
  5007. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5008. <EventID>201</EventID>
  5009. <Version>0</Version>
  5010. <Level>3</Level>
  5011. <Task>0</Task>
  5012. <Opcode>0</Opcode>
  5013. <Keywords>0x4000000000000000</Keywords>
  5014. <TimeCreated SystemTime="2016-08-23T23:45:23.822726600Z" />
  5015. <EventRecordID>111</EventRecordID>
  5016. <Correlation />
  5017. <Execution ProcessID="512" ThreadID="1688" />
  5018. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5019. <Computer>DESKTOP-D07KK79</Computer>
  5020. <Security UserID="S-1-5-18" />
  5021. </System>
  5022. <EventData>
  5023. </EventData>
  5024. </Event>
  5025.  
  5026. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5027. Source: Microsoft-Windows-DeviceSetupManager
  5028. Date: 8/23/2016 4:45:23 PM
  5029. Event ID: 202
  5030. Task Category: None
  5031. Level: Warning
  5032. Keywords:
  5033. User: SYSTEM
  5034. Computer: DESKTOP-D07KK79
  5035. Description:
  5036. The Network List Manager reports no connectivity to the internet.
  5037. Event Xml:
  5038. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5039. <System>
  5040. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5041. <EventID>202</EventID>
  5042. <Version>0</Version>
  5043. <Level>3</Level>
  5044. <Task>0</Task>
  5045. <Opcode>0</Opcode>
  5046. <Keywords>0x4000000000000000</Keywords>
  5047. <TimeCreated SystemTime="2016-08-23T23:45:23.822636300Z" />
  5048. <EventRecordID>110</EventRecordID>
  5049. <Correlation />
  5050. <Execution ProcessID="512" ThreadID="1688" />
  5051. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5052. <Computer>DESKTOP-D07KK79</Computer>
  5053. <Security UserID="S-1-5-18" />
  5054. </System>
  5055. <EventData>
  5056. </EventData>
  5057. </Event>
  5058.  
  5059. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5060. Source: Microsoft-Windows-DeviceSetupManager
  5061. Date: 8/23/2016 4:45:23 PM
  5062. Event ID: 200
  5063. Task Category: None
  5064. Level: Warning
  5065. Keywords:
  5066. User: SYSTEM
  5067. Computer: DESKTOP-D07KK79
  5068. Description:
  5069. A connection to the Windows Update service could not be established.
  5070. Event Xml:
  5071. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5072. <System>
  5073. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5074. <EventID>200</EventID>
  5075. <Version>0</Version>
  5076. <Level>3</Level>
  5077. <Task>0</Task>
  5078. <Opcode>0</Opcode>
  5079. <Keywords>0x4000000000000000</Keywords>
  5080. <TimeCreated SystemTime="2016-08-23T23:45:23.600470200Z" />
  5081. <EventRecordID>109</EventRecordID>
  5082. <Correlation />
  5083. <Execution ProcessID="512" ThreadID="1684" />
  5084. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5085. <Computer>DESKTOP-D07KK79</Computer>
  5086. <Security UserID="S-1-5-18" />
  5087. </System>
  5088. <EventData>
  5089. </EventData>
  5090. </Event>
  5091.  
  5092. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5093. Source: Microsoft-Windows-DeviceSetupManager
  5094. Date: 8/23/2016 4:45:23 PM
  5095. Event ID: 202
  5096. Task Category: None
  5097. Level: Warning
  5098. Keywords:
  5099. User: SYSTEM
  5100. Computer: DESKTOP-D07KK79
  5101. Description:
  5102. The Network List Manager reports no connectivity to the internet.
  5103. Event Xml:
  5104. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5105. <System>
  5106. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5107. <EventID>202</EventID>
  5108. <Version>0</Version>
  5109. <Level>3</Level>
  5110. <Task>0</Task>
  5111. <Opcode>0</Opcode>
  5112. <Keywords>0x4000000000000000</Keywords>
  5113. <TimeCreated SystemTime="2016-08-23T23:45:23.600370600Z" />
  5114. <EventRecordID>108</EventRecordID>
  5115. <Correlation />
  5116. <Execution ProcessID="512" ThreadID="1684" />
  5117. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5118. <Computer>DESKTOP-D07KK79</Computer>
  5119. <Security UserID="S-1-5-18" />
  5120. </System>
  5121. <EventData>
  5122. </EventData>
  5123. </Event>
  5124.  
  5125. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5126. Source: Microsoft-Windows-DeviceSetupManager
  5127. Date: 8/23/2016 4:45:23 PM
  5128. Event ID: 200
  5129. Task Category: None
  5130. Level: Warning
  5131. Keywords:
  5132. User: SYSTEM
  5133. Computer: DESKTOP-D07KK79
  5134. Description:
  5135. A connection to the Windows Update service could not be established.
  5136. Event Xml:
  5137. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5138. <System>
  5139. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5140. <EventID>200</EventID>
  5141. <Version>0</Version>
  5142. <Level>3</Level>
  5143. <Task>0</Task>
  5144. <Opcode>0</Opcode>
  5145. <Keywords>0x4000000000000000</Keywords>
  5146. <TimeCreated SystemTime="2016-08-23T23:45:23.599891400Z" />
  5147. <EventRecordID>107</EventRecordID>
  5148. <Correlation />
  5149. <Execution ProcessID="512" ThreadID="1660" />
  5150. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5151. <Computer>DESKTOP-D07KK79</Computer>
  5152. <Security UserID="S-1-5-18" />
  5153. </System>
  5154. <EventData>
  5155. </EventData>
  5156. </Event>
  5157.  
  5158. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5159. Source: Microsoft-Windows-DeviceSetupManager
  5160. Date: 8/23/2016 4:45:23 PM
  5161. Event ID: 202
  5162. Task Category: None
  5163. Level: Warning
  5164. Keywords:
  5165. User: SYSTEM
  5166. Computer: DESKTOP-D07KK79
  5167. Description:
  5168. The Network List Manager reports no connectivity to the internet.
  5169. Event Xml:
  5170. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5171. <System>
  5172. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5173. <EventID>202</EventID>
  5174. <Version>0</Version>
  5175. <Level>3</Level>
  5176. <Task>0</Task>
  5177. <Opcode>0</Opcode>
  5178. <Keywords>0x4000000000000000</Keywords>
  5179. <TimeCreated SystemTime="2016-08-23T23:45:23.599764100Z" />
  5180. <EventRecordID>106</EventRecordID>
  5181. <Correlation />
  5182. <Execution ProcessID="512" ThreadID="1660" />
  5183. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5184. <Computer>DESKTOP-D07KK79</Computer>
  5185. <Security UserID="S-1-5-18" />
  5186. </System>
  5187. <EventData>
  5188. </EventData>
  5189. </Event>
  5190.  
  5191. Log Name: System
  5192. Source: Microsoft-Windows-Kernel-PnP
  5193. Date: 8/23/2016 4:45:20 PM
  5194. Event ID: 219
  5195. Task Category: (212)
  5196. Level: Warning
  5197. Keywords:
  5198. User: SYSTEM
  5199. Computer: DESKTOP-D07KK79
  5200. Description:
  5201. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  5202. Event Xml:
  5203. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5204. <System>
  5205. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  5206. <EventID>219</EventID>
  5207. <Version>0</Version>
  5208. <Level>3</Level>
  5209. <Task>212</Task>
  5210. <Opcode>0</Opcode>
  5211. <Keywords>0x8000000000000000</Keywords>
  5212. <TimeCreated SystemTime="2016-08-23T23:45:20.341664400Z" />
  5213. <EventRecordID>626</EventRecordID>
  5214. <Correlation />
  5215. <Execution ProcessID="4" ThreadID="268" />
  5216. <Channel>System</Channel>
  5217. <Computer>DESKTOP-D07KK79</Computer>
  5218. <Security UserID="S-1-5-18" />
  5219. </System>
  5220. <EventData>
  5221. <Data Name="DriverNameLength">24</Data>
  5222. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  5223. <Data Name="Status">3221226341</Data>
  5224. <Data Name="FailureNameLength">14</Data>
  5225. <Data Name="FailureName">\Driver\WUDFRd</Data>
  5226. <Data Name="Version">0</Data>
  5227. </EventData>
  5228. </Event>
  5229.  
  5230. Log Name: Application
  5231. Source: Application Error
  5232. Date: 8/23/2016 4:44:22 PM
  5233. Event ID: 1000
  5234. Task Category: (100)
  5235. Level: Error
  5236. Keywords: Classic
  5237. User: N/A
  5238. Computer: DESKTOP-D07KK79
  5239. Description:
  5240. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  5241. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  5242. Exception code: 0xc0000409
  5243. Fault offset: 0x000d96c2
  5244. Faulting process id: 0xf14
  5245. Faulting application start time: 0x01d1fd98394457de
  5246. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  5247. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  5248. Report Id: eb256a70-1990-45f1-b720-19f8ee3dccda
  5249. Faulting package full name:
  5250. Faulting package-relative application ID:
  5251. Event Xml:
  5252. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5253. <System>
  5254. <Provider Name="Application Error" />
  5255. <EventID Qualifiers="0">1000</EventID>
  5256. <Level>2</Level>
  5257. <Task>100</Task>
  5258. <Keywords>0x80000000000000</Keywords>
  5259. <TimeCreated SystemTime="2016-08-23T23:44:22.383124200Z" />
  5260. <EventRecordID>370</EventRecordID>
  5261. <Channel>Application</Channel>
  5262. <Computer>DESKTOP-D07KK79</Computer>
  5263. <Security />
  5264. </System>
  5265. <EventData>
  5266. <Data>DipAwayMode.exe</Data>
  5267. <Data>0.0.0.0</Data>
  5268. <Data>00000000</Data>
  5269. <Data>KERNELBASE.dll</Data>
  5270. <Data>10.0.14393.0</Data>
  5271. <Data>57898e34</Data>
  5272. <Data>c0000409</Data>
  5273. <Data>000d96c2</Data>
  5274. <Data>f14</Data>
  5275. <Data>01d1fd98394457de</Data>
  5276. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  5277. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  5278. <Data>eb256a70-1990-45f1-b720-19f8ee3dccda</Data>
  5279. <Data>
  5280. </Data>
  5281. <Data>
  5282. </Data>
  5283. </EventData>
  5284. </Event>
  5285.  
  5286. Log Name: System
  5287. Source: Microsoft-Windows-DistributedCOM
  5288. Date: 8/23/2016 4:44:00 PM
  5289. Event ID: 10016
  5290. Task Category: None
  5291. Level: Error
  5292. Keywords: Classic
  5293. User: SYSTEM
  5294. Computer: DESKTOP-D07KK79
  5295. Description:
  5296. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  5297. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  5298. and APPID
  5299. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  5300. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  5301. Event Xml:
  5302. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5303. <System>
  5304. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  5305. <EventID Qualifiers="0">10016</EventID>
  5306. <Version>0</Version>
  5307. <Level>2</Level>
  5308. <Task>0</Task>
  5309. <Opcode>0</Opcode>
  5310. <Keywords>0x8080000000000000</Keywords>
  5311. <TimeCreated SystemTime="2016-08-23T23:44:00.905228300Z" />
  5312. <EventRecordID>596</EventRecordID>
  5313. <Correlation />
  5314. <Execution ProcessID="984" ThreadID="1616" />
  5315. <Channel>System</Channel>
  5316. <Computer>DESKTOP-D07KK79</Computer>
  5317. <Security UserID="S-1-5-18" />
  5318. </System>
  5319. <EventData>
  5320. <Data Name="param1">application-specific</Data>
  5321. <Data Name="param2">Local</Data>
  5322. <Data Name="param3">Activation</Data>
  5323. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  5324. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  5325. <Data Name="param6">NT AUTHORITY</Data>
  5326. <Data Name="param7">SYSTEM</Data>
  5327. <Data Name="param8">S-1-5-18</Data>
  5328. <Data Name="param9">LocalHost (Using LRPC)</Data>
  5329. <Data Name="param10">Unavailable</Data>
  5330. <Data Name="param11">Unavailable</Data>
  5331. </EventData>
  5332. </Event>
  5333.  
  5334. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5335. Source: Microsoft-Windows-DeviceSetupManager
  5336. Date: 8/23/2016 4:43:51 PM
  5337. Event ID: 201
  5338. Task Category: None
  5339. Level: Warning
  5340. Keywords:
  5341. User: SYSTEM
  5342. Computer: DESKTOP-D07KK79
  5343. Description:
  5344. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  5345. Event Xml:
  5346. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5347. <System>
  5348. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5349. <EventID>201</EventID>
  5350. <Version>0</Version>
  5351. <Level>3</Level>
  5352. <Task>0</Task>
  5353. <Opcode>0</Opcode>
  5354. <Keywords>0x4000000000000000</Keywords>
  5355. <TimeCreated SystemTime="2016-08-23T23:43:51.688890300Z" />
  5356. <EventRecordID>97</EventRecordID>
  5357. <Correlation />
  5358. <Execution ProcessID="544" ThreadID="1664" />
  5359. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5360. <Computer>DESKTOP-D07KK79</Computer>
  5361. <Security UserID="S-1-5-18" />
  5362. </System>
  5363. <EventData>
  5364. </EventData>
  5365. </Event>
  5366.  
  5367. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5368. Source: Microsoft-Windows-DeviceSetupManager
  5369. Date: 8/23/2016 4:43:51 PM
  5370. Event ID: 201
  5371. Task Category: None
  5372. Level: Warning
  5373. Keywords:
  5374. User: SYSTEM
  5375. Computer: DESKTOP-D07KK79
  5376. Description:
  5377. A connection to the Windows Metadata and Internet Services (WMIS) could not be established.
  5378. Event Xml:
  5379. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5380. <System>
  5381. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5382. <EventID>201</EventID>
  5383. <Version>0</Version>
  5384. <Level>3</Level>
  5385. <Task>0</Task>
  5386. <Opcode>0</Opcode>
  5387. <Keywords>0x4000000000000000</Keywords>
  5388. <TimeCreated SystemTime="2016-08-23T23:43:51.688814000Z" />
  5389. <EventRecordID>96</EventRecordID>
  5390. <Correlation />
  5391. <Execution ProcessID="544" ThreadID="1684" />
  5392. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5393. <Computer>DESKTOP-D07KK79</Computer>
  5394. <Security UserID="S-1-5-18" />
  5395. </System>
  5396. <EventData>
  5397. </EventData>
  5398. </Event>
  5399.  
  5400. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5401. Source: Microsoft-Windows-DeviceSetupManager
  5402. Date: 8/23/2016 4:43:51 PM
  5403. Event ID: 202
  5404. Task Category: None
  5405. Level: Warning
  5406. Keywords:
  5407. User: SYSTEM
  5408. Computer: DESKTOP-D07KK79
  5409. Description:
  5410. The Network List Manager reports no connectivity to the internet.
  5411. Event Xml:
  5412. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5413. <System>
  5414. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5415. <EventID>202</EventID>
  5416. <Version>0</Version>
  5417. <Level>3</Level>
  5418. <Task>0</Task>
  5419. <Opcode>0</Opcode>
  5420. <Keywords>0x4000000000000000</Keywords>
  5421. <TimeCreated SystemTime="2016-08-23T23:43:51.688805400Z" />
  5422. <EventRecordID>95</EventRecordID>
  5423. <Correlation />
  5424. <Execution ProcessID="544" ThreadID="1664" />
  5425. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5426. <Computer>DESKTOP-D07KK79</Computer>
  5427. <Security UserID="S-1-5-18" />
  5428. </System>
  5429. <EventData>
  5430. </EventData>
  5431. </Event>
  5432.  
  5433. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5434. Source: Microsoft-Windows-DeviceSetupManager
  5435. Date: 8/23/2016 4:43:51 PM
  5436. Event ID: 202
  5437. Task Category: None
  5438. Level: Warning
  5439. Keywords:
  5440. User: SYSTEM
  5441. Computer: DESKTOP-D07KK79
  5442. Description:
  5443. The Network List Manager reports no connectivity to the internet.
  5444. Event Xml:
  5445. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5446. <System>
  5447. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5448. <EventID>202</EventID>
  5449. <Version>0</Version>
  5450. <Level>3</Level>
  5451. <Task>0</Task>
  5452. <Opcode>0</Opcode>
  5453. <Keywords>0x4000000000000000</Keywords>
  5454. <TimeCreated SystemTime="2016-08-23T23:43:51.688730800Z" />
  5455. <EventRecordID>94</EventRecordID>
  5456. <Correlation />
  5457. <Execution ProcessID="544" ThreadID="1684" />
  5458. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5459. <Computer>DESKTOP-D07KK79</Computer>
  5460. <Security UserID="S-1-5-18" />
  5461. </System>
  5462. <EventData>
  5463. </EventData>
  5464. </Event>
  5465.  
  5466. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5467. Source: Microsoft-Windows-DeviceSetupManager
  5468. Date: 8/23/2016 4:43:51 PM
  5469. Event ID: 200
  5470. Task Category: None
  5471. Level: Warning
  5472. Keywords:
  5473. User: SYSTEM
  5474. Computer: DESKTOP-D07KK79
  5475. Description:
  5476. A connection to the Windows Update service could not be established.
  5477. Event Xml:
  5478. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5479. <System>
  5480. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5481. <EventID>200</EventID>
  5482. <Version>0</Version>
  5483. <Level>3</Level>
  5484. <Task>0</Task>
  5485. <Opcode>0</Opcode>
  5486. <Keywords>0x4000000000000000</Keywords>
  5487. <TimeCreated SystemTime="2016-08-23T23:43:51.458146500Z" />
  5488. <EventRecordID>93</EventRecordID>
  5489. <Correlation />
  5490. <Execution ProcessID="544" ThreadID="1684" />
  5491. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5492. <Computer>DESKTOP-D07KK79</Computer>
  5493. <Security UserID="S-1-5-18" />
  5494. </System>
  5495. <EventData>
  5496. </EventData>
  5497. </Event>
  5498.  
  5499. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5500. Source: Microsoft-Windows-DeviceSetupManager
  5501. Date: 8/23/2016 4:43:51 PM
  5502. Event ID: 202
  5503. Task Category: None
  5504. Level: Warning
  5505. Keywords:
  5506. User: SYSTEM
  5507. Computer: DESKTOP-D07KK79
  5508. Description:
  5509. The Network List Manager reports no connectivity to the internet.
  5510. Event Xml:
  5511. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5512. <System>
  5513. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5514. <EventID>202</EventID>
  5515. <Version>0</Version>
  5516. <Level>3</Level>
  5517. <Task>0</Task>
  5518. <Opcode>0</Opcode>
  5519. <Keywords>0x4000000000000000</Keywords>
  5520. <TimeCreated SystemTime="2016-08-23T23:43:51.457960100Z" />
  5521. <EventRecordID>92</EventRecordID>
  5522. <Correlation />
  5523. <Execution ProcessID="544" ThreadID="1684" />
  5524. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5525. <Computer>DESKTOP-D07KK79</Computer>
  5526. <Security UserID="S-1-5-18" />
  5527. </System>
  5528. <EventData>
  5529. </EventData>
  5530. </Event>
  5531.  
  5532. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5533. Source: Microsoft-Windows-DeviceSetupManager
  5534. Date: 8/23/2016 4:43:51 PM
  5535. Event ID: 200
  5536. Task Category: None
  5537. Level: Warning
  5538. Keywords:
  5539. User: SYSTEM
  5540. Computer: DESKTOP-D07KK79
  5541. Description:
  5542. A connection to the Windows Update service could not be established.
  5543. Event Xml:
  5544. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5545. <System>
  5546. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5547. <EventID>200</EventID>
  5548. <Version>0</Version>
  5549. <Level>3</Level>
  5550. <Task>0</Task>
  5551. <Opcode>0</Opcode>
  5552. <Keywords>0x4000000000000000</Keywords>
  5553. <TimeCreated SystemTime="2016-08-23T23:43:51.457590100Z" />
  5554. <EventRecordID>91</EventRecordID>
  5555. <Correlation />
  5556. <Execution ProcessID="544" ThreadID="1664" />
  5557. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5558. <Computer>DESKTOP-D07KK79</Computer>
  5559. <Security UserID="S-1-5-18" />
  5560. </System>
  5561. <EventData>
  5562. </EventData>
  5563. </Event>
  5564.  
  5565. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5566. Source: Microsoft-Windows-DeviceSetupManager
  5567. Date: 8/23/2016 4:43:51 PM
  5568. Event ID: 202
  5569. Task Category: None
  5570. Level: Warning
  5571. Keywords:
  5572. User: SYSTEM
  5573. Computer: DESKTOP-D07KK79
  5574. Description:
  5575. The Network List Manager reports no connectivity to the internet.
  5576. Event Xml:
  5577. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5578. <System>
  5579. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5580. <EventID>202</EventID>
  5581. <Version>0</Version>
  5582. <Level>3</Level>
  5583. <Task>0</Task>
  5584. <Opcode>0</Opcode>
  5585. <Keywords>0x4000000000000000</Keywords>
  5586. <TimeCreated SystemTime="2016-08-23T23:43:51.457382200Z" />
  5587. <EventRecordID>90</EventRecordID>
  5588. <Correlation />
  5589. <Execution ProcessID="544" ThreadID="1664" />
  5590. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5591. <Computer>DESKTOP-D07KK79</Computer>
  5592. <Security UserID="S-1-5-18" />
  5593. </System>
  5594. <EventData>
  5595. </EventData>
  5596. </Event>
  5597.  
  5598. Log Name: System
  5599. Source: Microsoft-Windows-Kernel-PnP
  5600. Date: 8/23/2016 4:43:48 PM
  5601. Event ID: 219
  5602. Task Category: (212)
  5603. Level: Warning
  5604. Keywords:
  5605. User: SYSTEM
  5606. Computer: DESKTOP-D07KK79
  5607. Description:
  5608. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  5609. Event Xml:
  5610. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5611. <System>
  5612. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  5613. <EventID>219</EventID>
  5614. <Version>0</Version>
  5615. <Level>3</Level>
  5616. <Task>212</Task>
  5617. <Opcode>0</Opcode>
  5618. <Keywords>0x8000000000000000</Keywords>
  5619. <TimeCreated SystemTime="2016-08-23T23:43:48.249755000Z" />
  5620. <EventRecordID>571</EventRecordID>
  5621. <Correlation />
  5622. <Execution ProcessID="4" ThreadID="396" />
  5623. <Channel>System</Channel>
  5624. <Computer>DESKTOP-D07KK79</Computer>
  5625. <Security UserID="S-1-5-18" />
  5626. </System>
  5627. <EventData>
  5628. <Data Name="DriverNameLength">24</Data>
  5629. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  5630. <Data Name="Status">3221226341</Data>
  5631. <Data Name="FailureNameLength">14</Data>
  5632. <Data Name="FailureName">\Driver\WUDFRd</Data>
  5633. <Data Name="Version">0</Data>
  5634. </EventData>
  5635. </Event>
  5636.  
  5637. Log Name: Application
  5638. Source: Application Error
  5639. Date: 8/23/2016 4:42:29 PM
  5640. Event ID: 1000
  5641. Task Category: (100)
  5642. Level: Error
  5643. Keywords: Classic
  5644. User: N/A
  5645. Computer: DESKTOP-D07KK79
  5646. Description:
  5647. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  5648. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  5649. Exception code: 0xc0000409
  5650. Fault offset: 0x000d96c2
  5651. Faulting process id: 0xf54
  5652. Faulting application start time: 0x01d1fd97f59dbf80
  5653. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  5654. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  5655. Report Id: 88d366e0-f5cc-4c17-ba08-e7557dda00e2
  5656. Faulting package full name:
  5657. Faulting package-relative application ID:
  5658. Event Xml:
  5659. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5660. <System>
  5661. <Provider Name="Application Error" />
  5662. <EventID Qualifiers="0">1000</EventID>
  5663. <Level>2</Level>
  5664. <Task>100</Task>
  5665. <Keywords>0x80000000000000</Keywords>
  5666. <TimeCreated SystemTime="2016-08-23T23:42:29.878618400Z" />
  5667. <EventRecordID>345</EventRecordID>
  5668. <Channel>Application</Channel>
  5669. <Computer>DESKTOP-D07KK79</Computer>
  5670. <Security />
  5671. </System>
  5672. <EventData>
  5673. <Data>DipAwayMode.exe</Data>
  5674. <Data>0.0.0.0</Data>
  5675. <Data>00000000</Data>
  5676. <Data>KERNELBASE.dll</Data>
  5677. <Data>10.0.14393.0</Data>
  5678. <Data>57898e34</Data>
  5679. <Data>c0000409</Data>
  5680. <Data>000d96c2</Data>
  5681. <Data>f54</Data>
  5682. <Data>01d1fd97f59dbf80</Data>
  5683. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  5684. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  5685. <Data>88d366e0-f5cc-4c17-ba08-e7557dda00e2</Data>
  5686. <Data>
  5687. </Data>
  5688. <Data>
  5689. </Data>
  5690. </EventData>
  5691. </Event>
  5692.  
  5693. Log Name: System
  5694. Source: Microsoft-Windows-DistributedCOM
  5695. Date: 8/23/2016 4:42:07 PM
  5696. Event ID: 10016
  5697. Task Category: None
  5698. Level: Error
  5699. Keywords: Classic
  5700. User: SYSTEM
  5701. Computer: DESKTOP-D07KK79
  5702. Description:
  5703. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  5704. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  5705. and APPID
  5706. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  5707. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  5708. Event Xml:
  5709. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5710. <System>
  5711. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  5712. <EventID Qualifiers="0">10016</EventID>
  5713. <Version>0</Version>
  5714. <Level>2</Level>
  5715. <Task>0</Task>
  5716. <Opcode>0</Opcode>
  5717. <Keywords>0x8080000000000000</Keywords>
  5718. <TimeCreated SystemTime="2016-08-23T23:42:07.310626800Z" />
  5719. <EventRecordID>539</EventRecordID>
  5720. <Correlation />
  5721. <Execution ProcessID="968" ThreadID="2872" />
  5722. <Channel>System</Channel>
  5723. <Computer>DESKTOP-D07KK79</Computer>
  5724. <Security UserID="S-1-5-18" />
  5725. </System>
  5726. <EventData>
  5727. <Data Name="param1">application-specific</Data>
  5728. <Data Name="param2">Local</Data>
  5729. <Data Name="param3">Activation</Data>
  5730. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  5731. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  5732. <Data Name="param6">NT AUTHORITY</Data>
  5733. <Data Name="param7">SYSTEM</Data>
  5734. <Data Name="param8">S-1-5-18</Data>
  5735. <Data Name="param9">LocalHost (Using LRPC)</Data>
  5736. <Data Name="param10">Unavailable</Data>
  5737. <Data Name="param11">Unavailable</Data>
  5738. </EventData>
  5739. </Event>
  5740.  
  5741. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5742. Source: Microsoft-Windows-DeviceSetupManager
  5743. Date: 8/23/2016 4:41:49 PM
  5744. Event ID: 200
  5745. Task Category: None
  5746. Level: Warning
  5747. Keywords:
  5748. User: SYSTEM
  5749. Computer: DESKTOP-D07KK79
  5750. Description:
  5751. A connection to the Windows Update service could not be established.
  5752. Event Xml:
  5753. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5754. <System>
  5755. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5756. <EventID>200</EventID>
  5757. <Version>0</Version>
  5758. <Level>3</Level>
  5759. <Task>0</Task>
  5760. <Opcode>0</Opcode>
  5761. <Keywords>0x4000000000000000</Keywords>
  5762. <TimeCreated SystemTime="2016-08-23T23:41:49.016782000Z" />
  5763. <EventRecordID>81</EventRecordID>
  5764. <Correlation />
  5765. <Execution ProcessID="484" ThreadID="1648" />
  5766. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5767. <Computer>DESKTOP-D07KK79</Computer>
  5768. <Security UserID="S-1-5-18" />
  5769. </System>
  5770. <EventData>
  5771. </EventData>
  5772. </Event>
  5773.  
  5774. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5775. Source: Microsoft-Windows-DeviceSetupManager
  5776. Date: 8/23/2016 4:41:49 PM
  5777. Event ID: 202
  5778. Task Category: None
  5779. Level: Warning
  5780. Keywords:
  5781. User: SYSTEM
  5782. Computer: DESKTOP-D07KK79
  5783. Description:
  5784. The Network List Manager reports no connectivity to the internet.
  5785. Event Xml:
  5786. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5787. <System>
  5788. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5789. <EventID>202</EventID>
  5790. <Version>0</Version>
  5791. <Level>3</Level>
  5792. <Task>0</Task>
  5793. <Opcode>0</Opcode>
  5794. <Keywords>0x4000000000000000</Keywords>
  5795. <TimeCreated SystemTime="2016-08-23T23:41:49.016668000Z" />
  5796. <EventRecordID>80</EventRecordID>
  5797. <Correlation />
  5798. <Execution ProcessID="484" ThreadID="1648" />
  5799. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5800. <Computer>DESKTOP-D07KK79</Computer>
  5801. <Security UserID="S-1-5-18" />
  5802. </System>
  5803. <EventData>
  5804. </EventData>
  5805. </Event>
  5806.  
  5807. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5808. Source: Microsoft-Windows-DeviceSetupManager
  5809. Date: 8/23/2016 4:41:49 PM
  5810. Event ID: 200
  5811. Task Category: None
  5812. Level: Warning
  5813. Keywords:
  5814. User: SYSTEM
  5815. Computer: DESKTOP-D07KK79
  5816. Description:
  5817. A connection to the Windows Update service could not be established.
  5818. Event Xml:
  5819. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5820. <System>
  5821. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5822. <EventID>200</EventID>
  5823. <Version>0</Version>
  5824. <Level>3</Level>
  5825. <Task>0</Task>
  5826. <Opcode>0</Opcode>
  5827. <Keywords>0x4000000000000000</Keywords>
  5828. <TimeCreated SystemTime="2016-08-23T23:41:49.016367000Z" />
  5829. <EventRecordID>79</EventRecordID>
  5830. <Correlation />
  5831. <Execution ProcessID="484" ThreadID="1628" />
  5832. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5833. <Computer>DESKTOP-D07KK79</Computer>
  5834. <Security UserID="S-1-5-18" />
  5835. </System>
  5836. <EventData>
  5837. </EventData>
  5838. </Event>
  5839.  
  5840. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  5841. Source: Microsoft-Windows-DeviceSetupManager
  5842. Date: 8/23/2016 4:41:49 PM
  5843. Event ID: 202
  5844. Task Category: None
  5845. Level: Warning
  5846. Keywords:
  5847. User: SYSTEM
  5848. Computer: DESKTOP-D07KK79
  5849. Description:
  5850. The Network List Manager reports no connectivity to the internet.
  5851. Event Xml:
  5852. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5853. <System>
  5854. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  5855. <EventID>202</EventID>
  5856. <Version>0</Version>
  5857. <Level>3</Level>
  5858. <Task>0</Task>
  5859. <Opcode>0</Opcode>
  5860. <Keywords>0x4000000000000000</Keywords>
  5861. <TimeCreated SystemTime="2016-08-23T23:41:49.016274900Z" />
  5862. <EventRecordID>78</EventRecordID>
  5863. <Correlation />
  5864. <Execution ProcessID="484" ThreadID="1628" />
  5865. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  5866. <Computer>DESKTOP-D07KK79</Computer>
  5867. <Security UserID="S-1-5-18" />
  5868. </System>
  5869. <EventData>
  5870. </EventData>
  5871. </Event>
  5872.  
  5873. Log Name: System
  5874. Source: Microsoft-Windows-Kernel-PnP
  5875. Date: 8/23/2016 4:41:38 PM
  5876. Event ID: 219
  5877. Task Category: (212)
  5878. Level: Warning
  5879. Keywords:
  5880. User: SYSTEM
  5881. Computer: DESKTOP-D07KK79
  5882. Description:
  5883. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  5884. Event Xml:
  5885. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5886. <System>
  5887. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  5888. <EventID>219</EventID>
  5889. <Version>0</Version>
  5890. <Level>3</Level>
  5891. <Task>212</Task>
  5892. <Opcode>0</Opcode>
  5893. <Keywords>0x8000000000000000</Keywords>
  5894. <TimeCreated SystemTime="2016-08-23T23:41:38.698612700Z" />
  5895. <EventRecordID>517</EventRecordID>
  5896. <Correlation />
  5897. <Execution ProcessID="4" ThreadID="400" />
  5898. <Channel>System</Channel>
  5899. <Computer>DESKTOP-D07KK79</Computer>
  5900. <Security UserID="S-1-5-18" />
  5901. </System>
  5902. <EventData>
  5903. <Data Name="DriverNameLength">24</Data>
  5904. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  5905. <Data Name="Status">3221226341</Data>
  5906. <Data Name="FailureNameLength">14</Data>
  5907. <Data Name="FailureName">\Driver\WUDFRd</Data>
  5908. <Data Name="Version">0</Data>
  5909. </EventData>
  5910. </Event>
  5911.  
  5912. Log Name: Application
  5913. Source: Application Error
  5914. Date: 8/23/2016 4:38:07 PM
  5915. Event ID: 1000
  5916. Task Category: (100)
  5917. Level: Error
  5918. Keywords: Classic
  5919. User: N/A
  5920. Computer: DESKTOP-D07KK79
  5921. Description:
  5922. Faulting application name: DipAwayMode.exe, version: 0.0.0.0, time stamp: 0x00000000
  5923. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  5924. Exception code: 0xc0000409
  5925. Fault offset: 0x000d96c2
  5926. Faulting process id: 0xf44
  5927. Faulting application start time: 0x01d1fd975b696c77
  5928. Faulting application path: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
  5929. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  5930. Report Id: 8de95021-0e20-486f-987d-36879c6a169d
  5931. Faulting package full name:
  5932. Faulting package-relative application ID:
  5933. Event Xml:
  5934. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5935. <System>
  5936. <Provider Name="Application Error" />
  5937. <EventID Qualifiers="0">1000</EventID>
  5938. <Level>2</Level>
  5939. <Task>100</Task>
  5940. <Keywords>0x80000000000000</Keywords>
  5941. <TimeCreated SystemTime="2016-08-23T23:38:07.909251000Z" />
  5942. <EventRecordID>288</EventRecordID>
  5943. <Channel>Application</Channel>
  5944. <Computer>DESKTOP-D07KK79</Computer>
  5945. <Security />
  5946. </System>
  5947. <EventData>
  5948. <Data>DipAwayMode.exe</Data>
  5949. <Data>0.0.0.0</Data>
  5950. <Data>00000000</Data>
  5951. <Data>KERNELBASE.dll</Data>
  5952. <Data>10.0.14393.0</Data>
  5953. <Data>57898e34</Data>
  5954. <Data>c0000409</Data>
  5955. <Data>000d96c2</Data>
  5956. <Data>f44</Data>
  5957. <Data>01d1fd975b696c77</Data>
  5958. <Data>C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  5959. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  5960. <Data>8de95021-0e20-486f-987d-36879c6a169d</Data>
  5961. <Data>
  5962. </Data>
  5963. <Data>
  5964. </Data>
  5965. </EventData>
  5966. </Event>
  5967.  
  5968. Log Name: System
  5969. Source: Microsoft-Windows-DistributedCOM
  5970. Date: 8/23/2016 4:37:48 PM
  5971. Event ID: 10016
  5972. Task Category: None
  5973. Level: Error
  5974. Keywords: Classic
  5975. User: SYSTEM
  5976. Computer: DESKTOP-D07KK79
  5977. Description:
  5978. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  5979. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  5980. and APPID
  5981. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  5982. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  5983. Event Xml:
  5984. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  5985. <System>
  5986. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  5987. <EventID Qualifiers="0">10016</EventID>
  5988. <Version>0</Version>
  5989. <Level>2</Level>
  5990. <Task>0</Task>
  5991. <Opcode>0</Opcode>
  5992. <Keywords>0x8080000000000000</Keywords>
  5993. <TimeCreated SystemTime="2016-08-23T23:37:48.285519400Z" />
  5994. <EventRecordID>481</EventRecordID>
  5995. <Correlation />
  5996. <Execution ProcessID="980" ThreadID="1452" />
  5997. <Channel>System</Channel>
  5998. <Computer>DESKTOP-D07KK79</Computer>
  5999. <Security UserID="S-1-5-18" />
  6000. </System>
  6001. <EventData>
  6002. <Data Name="param1">application-specific</Data>
  6003. <Data Name="param2">Local</Data>
  6004. <Data Name="param3">Activation</Data>
  6005. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  6006. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  6007. <Data Name="param6">NT AUTHORITY</Data>
  6008. <Data Name="param7">SYSTEM</Data>
  6009. <Data Name="param8">S-1-5-18</Data>
  6010. <Data Name="param9">LocalHost (Using LRPC)</Data>
  6011. <Data Name="param10">Unavailable</Data>
  6012. <Data Name="param11">Unavailable</Data>
  6013. </EventData>
  6014. </Event>
  6015.  
  6016. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6017. Source: Microsoft-Windows-DeviceSetupManager
  6018. Date: 8/23/2016 4:37:27 PM
  6019. Event ID: 200
  6020. Task Category: None
  6021. Level: Warning
  6022. Keywords:
  6023. User: SYSTEM
  6024. Computer: DESKTOP-D07KK79
  6025. Description:
  6026. A connection to the Windows Update service could not be established.
  6027. Event Xml:
  6028. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6029. <System>
  6030. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6031. <EventID>200</EventID>
  6032. <Version>0</Version>
  6033. <Level>3</Level>
  6034. <Task>0</Task>
  6035. <Opcode>0</Opcode>
  6036. <Keywords>0x4000000000000000</Keywords>
  6037. <TimeCreated SystemTime="2016-08-23T23:37:27.108270000Z" />
  6038. <EventRecordID>61</EventRecordID>
  6039. <Correlation />
  6040. <Execution ProcessID="612" ThreadID="1644" />
  6041. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6042. <Computer>DESKTOP-D07KK79</Computer>
  6043. <Security UserID="S-1-5-18" />
  6044. </System>
  6045. <EventData>
  6046. </EventData>
  6047. </Event>
  6048.  
  6049. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6050. Source: Microsoft-Windows-DeviceSetupManager
  6051. Date: 8/23/2016 4:37:27 PM
  6052. Event ID: 200
  6053. Task Category: None
  6054. Level: Warning
  6055. Keywords:
  6056. User: SYSTEM
  6057. Computer: DESKTOP-D07KK79
  6058. Description:
  6059. A connection to the Windows Update service could not be established.
  6060. Event Xml:
  6061. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6062. <System>
  6063. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6064. <EventID>200</EventID>
  6065. <Version>0</Version>
  6066. <Level>3</Level>
  6067. <Task>0</Task>
  6068. <Opcode>0</Opcode>
  6069. <Keywords>0x4000000000000000</Keywords>
  6070. <TimeCreated SystemTime="2016-08-23T23:37:27.108202800Z" />
  6071. <EventRecordID>60</EventRecordID>
  6072. <Correlation />
  6073. <Execution ProcessID="612" ThreadID="1628" />
  6074. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6075. <Computer>DESKTOP-D07KK79</Computer>
  6076. <Security UserID="S-1-5-18" />
  6077. </System>
  6078. <EventData>
  6079. </EventData>
  6080. </Event>
  6081.  
  6082. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6083. Source: Microsoft-Windows-DeviceSetupManager
  6084. Date: 8/23/2016 4:37:27 PM
  6085. Event ID: 202
  6086. Task Category: None
  6087. Level: Warning
  6088. Keywords:
  6089. User: SYSTEM
  6090. Computer: DESKTOP-D07KK79
  6091. Description:
  6092. The Network List Manager reports no connectivity to the internet.
  6093. Event Xml:
  6094. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6095. <System>
  6096. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6097. <EventID>202</EventID>
  6098. <Version>0</Version>
  6099. <Level>3</Level>
  6100. <Task>0</Task>
  6101. <Opcode>0</Opcode>
  6102. <Keywords>0x4000000000000000</Keywords>
  6103. <TimeCreated SystemTime="2016-08-23T23:37:27.108175000Z" />
  6104. <EventRecordID>59</EventRecordID>
  6105. <Correlation />
  6106. <Execution ProcessID="612" ThreadID="1644" />
  6107. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6108. <Computer>DESKTOP-D07KK79</Computer>
  6109. <Security UserID="S-1-5-18" />
  6110. </System>
  6111. <EventData>
  6112. </EventData>
  6113. </Event>
  6114.  
  6115. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6116. Source: Microsoft-Windows-DeviceSetupManager
  6117. Date: 8/23/2016 4:37:27 PM
  6118. Event ID: 200
  6119. Task Category: None
  6120. Level: Warning
  6121. Keywords:
  6122. User: SYSTEM
  6123. Computer: DESKTOP-D07KK79
  6124. Description:
  6125. A connection to the Windows Update service could not be established.
  6126. Event Xml:
  6127. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6128. <System>
  6129. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6130. <EventID>200</EventID>
  6131. <Version>0</Version>
  6132. <Level>3</Level>
  6133. <Task>0</Task>
  6134. <Opcode>0</Opcode>
  6135. <Keywords>0x4000000000000000</Keywords>
  6136. <TimeCreated SystemTime="2016-08-23T23:37:27.108166900Z" />
  6137. <EventRecordID>58</EventRecordID>
  6138. <Correlation />
  6139. <Execution ProcessID="612" ThreadID="1704" />
  6140. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6141. <Computer>DESKTOP-D07KK79</Computer>
  6142. <Security UserID="S-1-5-18" />
  6143. </System>
  6144. <EventData>
  6145. </EventData>
  6146. </Event>
  6147.  
  6148. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6149. Source: Microsoft-Windows-DeviceSetupManager
  6150. Date: 8/23/2016 4:37:27 PM
  6151. Event ID: 202
  6152. Task Category: None
  6153. Level: Warning
  6154. Keywords:
  6155. User: SYSTEM
  6156. Computer: DESKTOP-D07KK79
  6157. Description:
  6158. The Network List Manager reports no connectivity to the internet.
  6159. Event Xml:
  6160. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6161. <System>
  6162. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6163. <EventID>202</EventID>
  6164. <Version>0</Version>
  6165. <Level>3</Level>
  6166. <Task>0</Task>
  6167. <Opcode>0</Opcode>
  6168. <Keywords>0x4000000000000000</Keywords>
  6169. <TimeCreated SystemTime="2016-08-23T23:37:27.108116400Z" />
  6170. <EventRecordID>57</EventRecordID>
  6171. <Correlation />
  6172. <Execution ProcessID="612" ThreadID="1628" />
  6173. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6174. <Computer>DESKTOP-D07KK79</Computer>
  6175. <Security UserID="S-1-5-18" />
  6176. </System>
  6177. <EventData>
  6178. </EventData>
  6179. </Event>
  6180.  
  6181. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  6182. Source: Microsoft-Windows-DeviceSetupManager
  6183. Date: 8/23/2016 4:37:27 PM
  6184. Event ID: 202
  6185. Task Category: None
  6186. Level: Warning
  6187. Keywords:
  6188. User: SYSTEM
  6189. Computer: DESKTOP-D07KK79
  6190. Description:
  6191. The Network List Manager reports no connectivity to the internet.
  6192. Event Xml:
  6193. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6194. <System>
  6195. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  6196. <EventID>202</EventID>
  6197. <Version>0</Version>
  6198. <Level>3</Level>
  6199. <Task>0</Task>
  6200. <Opcode>0</Opcode>
  6201. <Keywords>0x4000000000000000</Keywords>
  6202. <TimeCreated SystemTime="2016-08-23T23:37:27.108067000Z" />
  6203. <EventRecordID>56</EventRecordID>
  6204. <Correlation />
  6205. <Execution ProcessID="612" ThreadID="1704" />
  6206. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  6207. <Computer>DESKTOP-D07KK79</Computer>
  6208. <Security UserID="S-1-5-18" />
  6209. </System>
  6210. <EventData>
  6211. </EventData>
  6212. </Event>
  6213.  
  6214. Log Name: System
  6215. Source: Microsoft-Windows-Kernel-PnP
  6216. Date: 8/23/2016 4:37:19 PM
  6217. Event ID: 219
  6218. Task Category: (212)
  6219. Level: Warning
  6220. Keywords:
  6221. User: SYSTEM
  6222. Computer: DESKTOP-D07KK79
  6223. Description:
  6224. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  6225. Event Xml:
  6226. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6227. <System>
  6228. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  6229. <EventID>219</EventID>
  6230. <Version>0</Version>
  6231. <Level>3</Level>
  6232. <Task>212</Task>
  6233. <Opcode>0</Opcode>
  6234. <Keywords>0x8000000000000000</Keywords>
  6235. <TimeCreated SystemTime="2016-08-23T23:37:19.227442400Z" />
  6236. <EventRecordID>455</EventRecordID>
  6237. <Correlation />
  6238. <Execution ProcessID="4" ThreadID="384" />
  6239. <Channel>System</Channel>
  6240. <Computer>DESKTOP-D07KK79</Computer>
  6241. <Security UserID="S-1-5-18" />
  6242. </System>
  6243. <EventData>
  6244. <Data Name="DriverNameLength">24</Data>
  6245. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  6246. <Data Name="Status">3221226341</Data>
  6247. <Data Name="FailureNameLength">14</Data>
  6248. <Data Name="FailureName">\Driver\WUDFRd</Data>
  6249. <Data Name="Version">0</Data>
  6250. </EventData>
  6251. </Event>
  6252.  
  6253. Log Name: System
  6254. Source: Microsoft-Windows-TaskScheduler
  6255. Date: 8/23/2016 4:35:15 PM
  6256. Event ID: 414
  6257. Task Category: Task Misconfiguration
  6258. Level: Warning
  6259. Keywords:
  6260. User: SYSTEM
  6261. Computer: DESKTOP-D07KK79
  6262. Description:
  6263. Task Scheduler service found a misconfiguration in the NT TASK\ASUS\GpuFanHelper definition. Additional Data: Error Value: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe.
  6264. Event Xml:
  6265. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6266. <System>
  6267. <Provider Name="Microsoft-Windows-TaskScheduler" Guid="{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}" />
  6268. <EventID>414</EventID>
  6269. <Version>0</Version>
  6270. <Level>3</Level>
  6271. <Task>414</Task>
  6272. <Opcode>0</Opcode>
  6273. <Keywords>0x4000000000000000</Keywords>
  6274. <TimeCreated SystemTime="2016-08-23T23:35:15.881140200Z" />
  6275. <EventRecordID>422</EventRecordID>
  6276. <Correlation />
  6277. <Execution ProcessID="480" ThreadID="2616" />
  6278. <Channel>System</Channel>
  6279. <Computer>DESKTOP-D07KK79</Computer>
  6280. <Security UserID="S-1-5-18" />
  6281. </System>
  6282. <EventData Name="TaskMisconfigured">
  6283. <Data Name="TaskName">NT TASK\ASUS\GpuFanHelper</Data>
  6284. <Data Name="Parameter">C:\Program Files (x86)\ASUS\AI Suite III\DIP4\GpuFanHelper.exe</Data>
  6285. </EventData>
  6286. </Event>
  6287.  
  6288. Log Name: System
  6289. Source: Microsoft-Windows-TaskScheduler
  6290. Date: 8/23/2016 4:35:15 PM
  6291. Event ID: 414
  6292. Task Category: Task Misconfiguration
  6293. Level: Warning
  6294. Keywords:
  6295. User: SYSTEM
  6296. Computer: DESKTOP-D07KK79
  6297. Description:
  6298. Task Scheduler service found a misconfiguration in the NT TASK\ASUS\ASUS DIPAwayMode definition. Additional Data: Error Value: C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe.
  6299. Event Xml:
  6300. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6301. <System>
  6302. <Provider Name="Microsoft-Windows-TaskScheduler" Guid="{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}" />
  6303. <EventID>414</EventID>
  6304. <Version>0</Version>
  6305. <Level>3</Level>
  6306. <Task>414</Task>
  6307. <Opcode>0</Opcode>
  6308. <Keywords>0x4000000000000000</Keywords>
  6309. <TimeCreated SystemTime="2016-08-23T23:35:15.842678800Z" />
  6310. <EventRecordID>421</EventRecordID>
  6311. <Correlation />
  6312. <Execution ProcessID="480" ThreadID="2840" />
  6313. <Channel>System</Channel>
  6314. <Computer>DESKTOP-D07KK79</Computer>
  6315. <Security UserID="S-1-5-18" />
  6316. </System>
  6317. <EventData Name="TaskMisconfigured">
  6318. <Data Name="TaskName">NT TASK\ASUS\ASUS DIPAwayMode</Data>
  6319. <Data Name="Parameter">C:\Program Files (x86)\ASUS\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe</Data>
  6320. </EventData>
  6321. </Event>
  6322.  
  6323. Log Name: System
  6324. Source: Microsoft-Windows-TaskScheduler
  6325. Date: 8/23/2016 4:34:51 PM
  6326. Event ID: 414
  6327. Task Category: Task Misconfiguration
  6328. Level: Warning
  6329. Keywords:
  6330. User: SYSTEM
  6331. Computer: DESKTOP-D07KK79
  6332. Description:
  6333. Task Scheduler service found a misconfiguration in the NT TASK\ASUS\ASUS AISuiteIII definition. Additional Data: Error Value: C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe.
  6334. Event Xml:
  6335. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6336. <System>
  6337. <Provider Name="Microsoft-Windows-TaskScheduler" Guid="{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}" />
  6338. <EventID>414</EventID>
  6339. <Version>0</Version>
  6340. <Level>3</Level>
  6341. <Task>414</Task>
  6342. <Opcode>0</Opcode>
  6343. <Keywords>0x4000000000000000</Keywords>
  6344. <TimeCreated SystemTime="2016-08-23T23:34:51.391994100Z" />
  6345. <EventRecordID>420</EventRecordID>
  6346. <Correlation />
  6347. <Execution ProcessID="480" ThreadID="2840" />
  6348. <Channel>System</Channel>
  6349. <Computer>DESKTOP-D07KK79</Computer>
  6350. <Security UserID="S-1-5-18" />
  6351. </System>
  6352. <EventData Name="TaskMisconfigured">
  6353. <Data Name="TaskName">NT TASK\ASUS\ASUS AISuiteIII</Data>
  6354. <Data Name="Parameter">C:\Program Files (x86)\ASUS\AI Suite III\AISuite3.exe</Data>
  6355. </EventData>
  6356. </Event>
  6357.  
  6358. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6359. Source: Microsoft-Windows-AppModel-Runtime
  6360. Date: 8/23/2016 4:33:32 PM
  6361. Event ID: 69
  6362. Task Category: None
  6363. Level: Error
  6364. Keywords: (70368744177664),Process
  6365. User: SYSTEM
  6366. Computer: DESKTOP-D07KK79
  6367. Description:
  6368. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.BingNews_4.13.47.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6369. Event Xml:
  6370. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6371. <System>
  6372. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6373. <EventID>69</EventID>
  6374. <Version>0</Version>
  6375. <Level>2</Level>
  6376. <Task>0</Task>
  6377. <Opcode>0</Opcode>
  6378. <Keywords>0x2000400000000001</Keywords>
  6379. <TimeCreated SystemTime="2016-08-23T23:33:32.711043300Z" />
  6380. <EventRecordID>219</EventRecordID>
  6381. <Correlation ActivityID="{29A47941-FD96-0006-C286-A42996FDD101}" />
  6382. <Execution ProcessID="4072" ThreadID="6780" />
  6383. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6384. <Computer>DESKTOP-D07KK79</Computer>
  6385. <Security UserID="S-1-5-18" />
  6386. </System>
  6387. <EventData>
  6388. <Data Name="ErrorCode">1168</Data>
  6389. <Data Name="PackageFullName">Microsoft.BingNews_4.13.47.0_x86__8wekyb3d8bbwe</Data>
  6390. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6391. <Data Name="DesiredStatus">32</Data>
  6392. <Data Name="CurrentStatus">0</Data>
  6393. </EventData>
  6394. </Event>
  6395.  
  6396. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6397. Source: Microsoft-Windows-AppModel-Runtime
  6398. Date: 8/23/2016 4:33:30 PM
  6399. Event ID: 69
  6400. Task Category: None
  6401. Level: Error
  6402. Keywords: (70368744177664),Process
  6403. User: SYSTEM
  6404. Computer: DESKTOP-D07KK79
  6405. Description:
  6406. Failed with 0x490 modifying AppModel Runtime status for package PandoraMediaInc.29680B314EFC2_10.0.7.0_x64__n619g4d5j0fnw for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6407. Event Xml:
  6408. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6409. <System>
  6410. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6411. <EventID>69</EventID>
  6412. <Version>0</Version>
  6413. <Level>2</Level>
  6414. <Task>0</Task>
  6415. <Opcode>0</Opcode>
  6416. <Keywords>0x2000400000000001</Keywords>
  6417. <TimeCreated SystemTime="2016-08-23T23:33:30.480207000Z" />
  6418. <EventRecordID>215</EventRecordID>
  6419. <Correlation ActivityID="{29A47941-FD96-0004-E28A-A42996FDD101}" />
  6420. <Execution ProcessID="4072" ThreadID="6760" />
  6421. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6422. <Computer>DESKTOP-D07KK79</Computer>
  6423. <Security UserID="S-1-5-18" />
  6424. </System>
  6425. <EventData>
  6426. <Data Name="ErrorCode">1168</Data>
  6427. <Data Name="PackageFullName">PandoraMediaInc.29680B314EFC2_10.0.7.0_x64__n619g4d5j0fnw</Data>
  6428. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6429. <Data Name="DesiredStatus">32</Data>
  6430. <Data Name="CurrentStatus">0</Data>
  6431. </EventData>
  6432. </Event>
  6433.  
  6434. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6435. Source: Microsoft-Windows-AppModel-Runtime
  6436. Date: 8/23/2016 4:33:29 PM
  6437. Event ID: 69
  6438. Task Category: None
  6439. Level: Error
  6440. Keywords: (70368744177664),Process
  6441. User: SYSTEM
  6442. Computer: DESKTOP-D07KK79
  6443. Description:
  6444. Failed with 0x490 modifying AppModel Runtime status for package 9E2F88E3.Twitter_5.2.0.0_x86__wgeqdkkx372wm for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6445. Event Xml:
  6446. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6447. <System>
  6448. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6449. <EventID>69</EventID>
  6450. <Version>0</Version>
  6451. <Level>2</Level>
  6452. <Task>0</Task>
  6453. <Opcode>0</Opcode>
  6454. <Keywords>0x2000400000000001</Keywords>
  6455. <TimeCreated SystemTime="2016-08-23T23:33:29.630234800Z" />
  6456. <EventRecordID>213</EventRecordID>
  6457. <Correlation ActivityID="{29A47941-FD96-0003-3484-A42996FDD101}" />
  6458. <Execution ProcessID="4072" ThreadID="6780" />
  6459. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6460. <Computer>DESKTOP-D07KK79</Computer>
  6461. <Security UserID="S-1-5-18" />
  6462. </System>
  6463. <EventData>
  6464. <Data Name="ErrorCode">1168</Data>
  6465. <Data Name="PackageFullName">9E2F88E3.Twitter_5.2.0.0_x86__wgeqdkkx372wm</Data>
  6466. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6467. <Data Name="DesiredStatus">32</Data>
  6468. <Data Name="CurrentStatus">0</Data>
  6469. </EventData>
  6470. </Event>
  6471.  
  6472. Log Name: Application
  6473. Source: Application Error
  6474. Date: 8/23/2016 4:33:27 PM
  6475. Event ID: 1000
  6476. Task Category: (100)
  6477. Level: Error
  6478. Keywords: Classic
  6479. User: N/A
  6480. Computer: DESKTOP-D07KK79
  6481. Description:
  6482. Faulting application name: aprp.exe, version: 1.0.0.28, time stamp: 0x5490e08f
  6483. Faulting module name: KERNELBASE.dll, version: 10.0.14393.0, time stamp: 0x57898e34
  6484. Exception code: 0xc0000409
  6485. Fault offset: 0x000d96c2
  6486. Faulting process id: 0xf00
  6487. Faulting application start time: 0x01d1fd964893148d
  6488. Faulting application path: C:\Program Files (x86)\ASUS\APRP\aprp.exe
  6489. Faulting module path: C:\WINDOWS\System32\KERNELBASE.dll
  6490. Report Id: 804da0f1-58fb-48ca-bbec-d7b956021fb4
  6491. Faulting package full name:
  6492. Faulting package-relative application ID:
  6493. Event Xml:
  6494. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6495. <System>
  6496. <Provider Name="Application Error" />
  6497. <EventID Qualifiers="0">1000</EventID>
  6498. <Level>2</Level>
  6499. <Task>100</Task>
  6500. <Keywords>0x80000000000000</Keywords>
  6501. <TimeCreated SystemTime="2016-08-23T23:33:27.260938600Z" />
  6502. <EventRecordID>254</EventRecordID>
  6503. <Channel>Application</Channel>
  6504. <Computer>DESKTOP-D07KK79</Computer>
  6505. <Security />
  6506. </System>
  6507. <EventData>
  6508. <Data>aprp.exe</Data>
  6509. <Data>1.0.0.28</Data>
  6510. <Data>5490e08f</Data>
  6511. <Data>KERNELBASE.dll</Data>
  6512. <Data>10.0.14393.0</Data>
  6513. <Data>57898e34</Data>
  6514. <Data>c0000409</Data>
  6515. <Data>000d96c2</Data>
  6516. <Data>f00</Data>
  6517. <Data>01d1fd964893148d</Data>
  6518. <Data>C:\Program Files (x86)\ASUS\APRP\aprp.exe</Data>
  6519. <Data>C:\WINDOWS\System32\KERNELBASE.dll</Data>
  6520. <Data>804da0f1-58fb-48ca-bbec-d7b956021fb4</Data>
  6521. <Data>
  6522. </Data>
  6523. <Data>
  6524. </Data>
  6525. </EventData>
  6526. </Event>
  6527.  
  6528. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6529. Source: Microsoft-Windows-AppModel-Runtime
  6530. Date: 8/23/2016 4:33:00 PM
  6531. Event ID: 69
  6532. Task Category: None
  6533. Level: Error
  6534. Keywords: (70368744177664),Process
  6535. User: SYSTEM
  6536. Computer: DESKTOP-D07KK79
  6537. Description:
  6538. Failed with 0x490 modifying AppModel Runtime status for package 4DF9E0F8.Netflix_6.11.33.0_x64__mcm4njqhnhss8 for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6539. Event Xml:
  6540. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6541. <System>
  6542. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6543. <EventID>69</EventID>
  6544. <Version>0</Version>
  6545. <Level>2</Level>
  6546. <Task>0</Task>
  6547. <Opcode>0</Opcode>
  6548. <Keywords>0x2000400000000001</Keywords>
  6549. <TimeCreated SystemTime="2016-08-23T23:33:00.523217100Z" />
  6550. <EventRecordID>119</EventRecordID>
  6551. <Correlation ActivityID="{29A47941-FD96-0003-1F82-A42996FDD101}" />
  6552. <Execution ProcessID="4072" ThreadID="6776" />
  6553. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6554. <Computer>DESKTOP-D07KK79</Computer>
  6555. <Security UserID="S-1-5-18" />
  6556. </System>
  6557. <EventData>
  6558. <Data Name="ErrorCode">1168</Data>
  6559. <Data Name="PackageFullName">4DF9E0F8.Netflix_6.11.33.0_x64__mcm4njqhnhss8</Data>
  6560. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6561. <Data Name="DesiredStatus">32</Data>
  6562. <Data Name="CurrentStatus">0</Data>
  6563. </EventData>
  6564. </Event>
  6565.  
  6566. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6567. Source: Microsoft-Windows-AppModel-Runtime
  6568. Date: 8/23/2016 4:31:07 PM
  6569. Event ID: 69
  6570. Task Category: None
  6571. Level: Error
  6572. Keywords: (70368744177664),Process
  6573. User: SYSTEM
  6574. Computer: DESKTOP-D07KK79
  6575. Description:
  6576. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.3DBuilder_11.0.47.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6577. Event Xml:
  6578. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6579. <System>
  6580. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6581. <EventID>69</EventID>
  6582. <Version>0</Version>
  6583. <Level>2</Level>
  6584. <Task>0</Task>
  6585. <Opcode>0</Opcode>
  6586. <Keywords>0x2000400000000001</Keywords>
  6587. <TimeCreated SystemTime="2016-08-23T23:31:07.005850900Z" />
  6588. <EventRecordID>113</EventRecordID>
  6589. <Correlation ActivityID="{29A47941-FD96-0007-AE7D-A42996FDD101}" />
  6590. <Execution ProcessID="4072" ThreadID="6760" />
  6591. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6592. <Computer>DESKTOP-D07KK79</Computer>
  6593. <Security UserID="S-1-5-18" />
  6594. </System>
  6595. <EventData>
  6596. <Data Name="ErrorCode">1168</Data>
  6597. <Data Name="PackageFullName">Microsoft.3DBuilder_11.0.47.0_x64__8wekyb3d8bbwe</Data>
  6598. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6599. <Data Name="DesiredStatus">32</Data>
  6600. <Data Name="CurrentStatus">0</Data>
  6601. </EventData>
  6602. </Event>
  6603.  
  6604. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6605. Source: Microsoft-Windows-AppModel-Runtime
  6606. Date: 8/23/2016 4:31:05 PM
  6607. Event ID: 69
  6608. Task Category: None
  6609. Level: Error
  6610. Keywords: (70368744177664),Process
  6611. User: SYSTEM
  6612. Computer: DESKTOP-D07KK79
  6613. Description:
  6614. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Messaging_3.19.1001.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6615. Event Xml:
  6616. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6617. <System>
  6618. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6619. <EventID>69</EventID>
  6620. <Version>0</Version>
  6621. <Level>2</Level>
  6622. <Task>0</Task>
  6623. <Opcode>0</Opcode>
  6624. <Keywords>0x2000400000000001</Keywords>
  6625. <TimeCreated SystemTime="2016-08-23T23:31:05.808237900Z" />
  6626. <EventRecordID>111</EventRecordID>
  6627. <Correlation ActivityID="{29A47941-FD96-0000-7B80-A42996FDD101}" />
  6628. <Execution ProcessID="4072" ThreadID="6776" />
  6629. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6630. <Computer>DESKTOP-D07KK79</Computer>
  6631. <Security UserID="S-1-5-18" />
  6632. </System>
  6633. <EventData>
  6634. <Data Name="ErrorCode">1168</Data>
  6635. <Data Name="PackageFullName">Microsoft.Messaging_3.19.1001.0_x86__8wekyb3d8bbwe</Data>
  6636. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6637. <Data Name="DesiredStatus">32</Data>
  6638. <Data Name="CurrentStatus">0</Data>
  6639. </EventData>
  6640. </Event>
  6641.  
  6642. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6643. Source: Microsoft-Windows-AppModel-Runtime
  6644. Date: 8/23/2016 4:31:04 PM
  6645. Event ID: 69
  6646. Task Category: None
  6647. Level: Error
  6648. Keywords: (70368744177664),Process
  6649. User: SYSTEM
  6650. Computer: DESKTOP-D07KK79
  6651. Description:
  6652. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftOfficeHub_17.6801.23751.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6653. Event Xml:
  6654. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6655. <System>
  6656. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6657. <EventID>69</EventID>
  6658. <Version>0</Version>
  6659. <Level>2</Level>
  6660. <Task>0</Task>
  6661. <Opcode>0</Opcode>
  6662. <Keywords>0x2000400000000001</Keywords>
  6663. <TimeCreated SystemTime="2016-08-23T23:31:04.586033500Z" />
  6664. <EventRecordID>109</EventRecordID>
  6665. <Correlation ActivityID="{29A47941-FD96-0007-9E7D-A42996FDD101}" />
  6666. <Execution ProcessID="4072" ThreadID="6780" />
  6667. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6668. <Computer>DESKTOP-D07KK79</Computer>
  6669. <Security UserID="S-1-5-18" />
  6670. </System>
  6671. <EventData>
  6672. <Data Name="ErrorCode">1168</Data>
  6673. <Data Name="PackageFullName">Microsoft.MicrosoftOfficeHub_17.6801.23751.0_x64__8wekyb3d8bbwe</Data>
  6674. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6675. <Data Name="DesiredStatus">32</Data>
  6676. <Data Name="CurrentStatus">0</Data>
  6677. </EventData>
  6678. </Event>
  6679.  
  6680. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6681. Source: Microsoft-Windows-AppModel-Runtime
  6682. Date: 8/23/2016 4:31:03 PM
  6683. Event ID: 69
  6684. Task Category: None
  6685. Level: Error
  6686. Keywords: (70368744177664),Process
  6687. User: SYSTEM
  6688. Computer: DESKTOP-D07KK79
  6689. Description:
  6690. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftSolitaireCollection_3.9.5100.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6691. Event Xml:
  6692. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6693. <System>
  6694. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6695. <EventID>69</EventID>
  6696. <Version>0</Version>
  6697. <Level>2</Level>
  6698. <Task>0</Task>
  6699. <Opcode>0</Opcode>
  6700. <Keywords>0x2000400000000001</Keywords>
  6701. <TimeCreated SystemTime="2016-08-23T23:31:03.156719500Z" />
  6702. <EventRecordID>105</EventRecordID>
  6703. <Correlation ActivityID="{29A47941-FD96-0007-957D-A42996FDD101}" />
  6704. <Execution ProcessID="4072" ThreadID="6780" />
  6705. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6706. <Computer>DESKTOP-D07KK79</Computer>
  6707. <Security UserID="S-1-5-18" />
  6708. </System>
  6709. <EventData>
  6710. <Data Name="ErrorCode">1168</Data>
  6711. <Data Name="PackageFullName">Microsoft.MicrosoftSolitaireCollection_3.9.5100.0_x64__8wekyb3d8bbwe</Data>
  6712. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6713. <Data Name="DesiredStatus">32</Data>
  6714. <Data Name="CurrentStatus">0</Data>
  6715. </EventData>
  6716. </Event>
  6717.  
  6718. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6719. Source: Microsoft-Windows-AppModel-Runtime
  6720. Date: 8/23/2016 4:31:03 PM
  6721. Event ID: 69
  6722. Task Category: None
  6723. Level: Error
  6724. Keywords: (70368744177664),Process
  6725. User: SYSTEM
  6726. Computer: DESKTOP-D07KK79
  6727. Description:
  6728. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Advertising.Xaml_10.0.1605.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6729. Event Xml:
  6730. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6731. <System>
  6732. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6733. <EventID>69</EventID>
  6734. <Version>0</Version>
  6735. <Level>2</Level>
  6736. <Task>0</Task>
  6737. <Opcode>0</Opcode>
  6738. <Keywords>0x2000400000000001</Keywords>
  6739. <TimeCreated SystemTime="2016-08-23T23:31:03.156676600Z" />
  6740. <EventRecordID>104</EventRecordID>
  6741. <Correlation ActivityID="{29A47941-FD96-0007-957D-A42996FDD101}" />
  6742. <Execution ProcessID="4072" ThreadID="6780" />
  6743. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6744. <Computer>DESKTOP-D07KK79</Computer>
  6745. <Security UserID="S-1-5-18" />
  6746. </System>
  6747. <EventData>
  6748. <Data Name="ErrorCode">1168</Data>
  6749. <Data Name="PackageFullName">Microsoft.Advertising.Xaml_10.0.1605.0_x64__8wekyb3d8bbwe</Data>
  6750. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6751. <Data Name="DesiredStatus">32</Data>
  6752. <Data Name="CurrentStatus">0</Data>
  6753. </EventData>
  6754. </Event>
  6755.  
  6756. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6757. Source: Microsoft-Windows-AppModel-Runtime
  6758. Date: 8/23/2016 4:31:03 PM
  6759. Event ID: 69
  6760. Task Category: None
  6761. Level: Error
  6762. Keywords: (70368744177664),Process
  6763. User: SYSTEM
  6764. Computer: DESKTOP-D07KK79
  6765. Description:
  6766. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Advertising.Xaml_10.0.1605.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6767. Event Xml:
  6768. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6769. <System>
  6770. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6771. <EventID>69</EventID>
  6772. <Version>0</Version>
  6773. <Level>2</Level>
  6774. <Task>0</Task>
  6775. <Opcode>0</Opcode>
  6776. <Keywords>0x2000400000000001</Keywords>
  6777. <TimeCreated SystemTime="2016-08-23T23:31:03.156624400Z" />
  6778. <EventRecordID>103</EventRecordID>
  6779. <Correlation ActivityID="{29A47941-FD96-0007-957D-A42996FDD101}" />
  6780. <Execution ProcessID="4072" ThreadID="6780" />
  6781. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6782. <Computer>DESKTOP-D07KK79</Computer>
  6783. <Security UserID="S-1-5-18" />
  6784. </System>
  6785. <EventData>
  6786. <Data Name="ErrorCode">1168</Data>
  6787. <Data Name="PackageFullName">Microsoft.Advertising.Xaml_10.0.1605.0_x86__8wekyb3d8bbwe</Data>
  6788. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6789. <Data Name="DesiredStatus">32</Data>
  6790. <Data Name="CurrentStatus">0</Data>
  6791. </EventData>
  6792. </Event>
  6793.  
  6794. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6795. Source: Microsoft-Windows-AppModel-Runtime
  6796. Date: 8/23/2016 4:31:01 PM
  6797. Event ID: 69
  6798. Task Category: None
  6799. Level: Error
  6800. Keywords: (70368744177664),Process
  6801. User: SYSTEM
  6802. Computer: DESKTOP-D07KK79
  6803. Description:
  6804. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftStickyNotes_1.0.136.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6805. Event Xml:
  6806. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6807. <System>
  6808. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6809. <EventID>69</EventID>
  6810. <Version>0</Version>
  6811. <Level>2</Level>
  6812. <Task>0</Task>
  6813. <Opcode>0</Opcode>
  6814. <Keywords>0x2000400000000001</Keywords>
  6815. <TimeCreated SystemTime="2016-08-23T23:31:01.218902200Z" />
  6816. <EventRecordID>101</EventRecordID>
  6817. <Correlation ActivityID="{29A47941-FD96-0002-6E7F-A42996FDD101}" />
  6818. <Execution ProcessID="4072" ThreadID="6780" />
  6819. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6820. <Computer>DESKTOP-D07KK79</Computer>
  6821. <Security UserID="S-1-5-18" />
  6822. </System>
  6823. <EventData>
  6824. <Data Name="ErrorCode">1168</Data>
  6825. <Data Name="PackageFullName">Microsoft.MicrosoftStickyNotes_1.0.136.0_x64__8wekyb3d8bbwe</Data>
  6826. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6827. <Data Name="DesiredStatus">32</Data>
  6828. <Data Name="CurrentStatus">0</Data>
  6829. </EventData>
  6830. </Event>
  6831.  
  6832. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6833. Source: Microsoft-Windows-AppModel-Runtime
  6834. Date: 8/23/2016 4:31:00 PM
  6835. Event ID: 69
  6836. Task Category: None
  6837. Level: Error
  6838. Keywords: (70368744177664),Process
  6839. User: SYSTEM
  6840. Computer: DESKTOP-D07KK79
  6841. Description:
  6842. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Office.OneNote_17.6868.57981.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6843. Event Xml:
  6844. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6845. <System>
  6846. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6847. <EventID>69</EventID>
  6848. <Version>0</Version>
  6849. <Level>2</Level>
  6850. <Task>0</Task>
  6851. <Opcode>0</Opcode>
  6852. <Keywords>0x2000400000000001</Keywords>
  6853. <TimeCreated SystemTime="2016-08-23T23:31:00.252177200Z" />
  6854. <EventRecordID>99</EventRecordID>
  6855. <Correlation ActivityID="{29A47941-FD96-0000-5680-A42996FDD101}" />
  6856. <Execution ProcessID="4072" ThreadID="6776" />
  6857. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6858. <Computer>DESKTOP-D07KK79</Computer>
  6859. <Security UserID="S-1-5-18" />
  6860. </System>
  6861. <EventData>
  6862. <Data Name="ErrorCode">1168</Data>
  6863. <Data Name="PackageFullName">Microsoft.Office.OneNote_17.6868.57981.0_x64__8wekyb3d8bbwe</Data>
  6864. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6865. <Data Name="DesiredStatus">32</Data>
  6866. <Data Name="CurrentStatus">0</Data>
  6867. </EventData>
  6868. </Event>
  6869.  
  6870. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6871. Source: Microsoft-Windows-AppModel-Runtime
  6872. Date: 8/23/2016 4:30:59 PM
  6873. Event ID: 69
  6874. Task Category: None
  6875. Level: Error
  6876. Keywords: (70368744177664),Process
  6877. User: SYSTEM
  6878. Computer: DESKTOP-D07KK79
  6879. Description:
  6880. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.OneConnect_1.1605.17.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6881. Event Xml:
  6882. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6883. <System>
  6884. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6885. <EventID>69</EventID>
  6886. <Version>0</Version>
  6887. <Level>2</Level>
  6888. <Task>0</Task>
  6889. <Opcode>0</Opcode>
  6890. <Keywords>0x2000400000000001</Keywords>
  6891. <TimeCreated SystemTime="2016-08-23T23:30:59.044909100Z" />
  6892. <EventRecordID>97</EventRecordID>
  6893. <Correlation ActivityID="{29A47941-FD96-0002-5D7F-A42996FDD101}" />
  6894. <Execution ProcessID="4072" ThreadID="6780" />
  6895. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6896. <Computer>DESKTOP-D07KK79</Computer>
  6897. <Security UserID="S-1-5-18" />
  6898. </System>
  6899. <EventData>
  6900. <Data Name="ErrorCode">1168</Data>
  6901. <Data Name="PackageFullName">Microsoft.OneConnect_1.1605.17.0_x64__8wekyb3d8bbwe</Data>
  6902. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6903. <Data Name="DesiredStatus">32</Data>
  6904. <Data Name="CurrentStatus">0</Data>
  6905. </EventData>
  6906. </Event>
  6907.  
  6908. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6909. Source: Microsoft-Windows-AppModel-Runtime
  6910. Date: 8/23/2016 4:30:57 PM
  6911. Event ID: 69
  6912. Task Category: None
  6913. Level: Error
  6914. Keywords: (70368744177664),Process
  6915. User: SYSTEM
  6916. Computer: DESKTOP-D07KK79
  6917. Description:
  6918. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6919. Event Xml:
  6920. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6921. <System>
  6922. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6923. <EventID>69</EventID>
  6924. <Version>0</Version>
  6925. <Level>2</Level>
  6926. <Task>0</Task>
  6927. <Opcode>0</Opcode>
  6928. <Keywords>0x2000400000000001</Keywords>
  6929. <TimeCreated SystemTime="2016-08-23T23:30:57.904415600Z" />
  6930. <EventRecordID>95</EventRecordID>
  6931. <Correlation ActivityID="{29A47941-FD96-0003-0580-A42996FDD101}" />
  6932. <Execution ProcessID="4072" ThreadID="6776" />
  6933. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6934. <Computer>DESKTOP-D07KK79</Computer>
  6935. <Security UserID="S-1-5-18" />
  6936. </System>
  6937. <EventData>
  6938. <Data Name="ErrorCode">1168</Data>
  6939. <Data Name="PackageFullName">Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe</Data>
  6940. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6941. <Data Name="DesiredStatus">32</Data>
  6942. <Data Name="CurrentStatus">0</Data>
  6943. </EventData>
  6944. </Event>
  6945.  
  6946. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6947. Source: Microsoft-Windows-AppModel-Runtime
  6948. Date: 8/23/2016 4:30:56 PM
  6949. Event ID: 69
  6950. Task Category: None
  6951. Level: Error
  6952. Keywords: (70368744177664),Process
  6953. User: SYSTEM
  6954. Computer: DESKTOP-D07KK79
  6955. Description:
  6956. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.StorePurchaseApp_1.0.45.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6957. Event Xml:
  6958. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6959. <System>
  6960. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6961. <EventID>69</EventID>
  6962. <Version>0</Version>
  6963. <Level>2</Level>
  6964. <Task>0</Task>
  6965. <Opcode>0</Opcode>
  6966. <Keywords>0x2000400000000001</Keywords>
  6967. <TimeCreated SystemTime="2016-08-23T23:30:56.946993700Z" />
  6968. <EventRecordID>93</EventRecordID>
  6969. <Correlation ActivityID="{29A47941-FD96-0007-7D7D-A42996FDD101}" />
  6970. <Execution ProcessID="4072" ThreadID="6780" />
  6971. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  6972. <Computer>DESKTOP-D07KK79</Computer>
  6973. <Security UserID="S-1-5-18" />
  6974. </System>
  6975. <EventData>
  6976. <Data Name="ErrorCode">1168</Data>
  6977. <Data Name="PackageFullName">Microsoft.StorePurchaseApp_1.0.45.0_x64__8wekyb3d8bbwe</Data>
  6978. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  6979. <Data Name="DesiredStatus">32</Data>
  6980. <Data Name="CurrentStatus">0</Data>
  6981. </EventData>
  6982. </Event>
  6983.  
  6984. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  6985. Source: Microsoft-Windows-AppModel-Runtime
  6986. Date: 8/23/2016 4:30:55 PM
  6987. Event ID: 69
  6988. Task Category: None
  6989. Level: Error
  6990. Keywords: (70368744177664),Process
  6991. User: SYSTEM
  6992. Computer: DESKTOP-D07KK79
  6993. Description:
  6994. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  6995. Event Xml:
  6996. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  6997. <System>
  6998. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  6999. <EventID>69</EventID>
  7000. <Version>0</Version>
  7001. <Level>2</Level>
  7002. <Task>0</Task>
  7003. <Opcode>0</Opcode>
  7004. <Keywords>0x2000400000000001</Keywords>
  7005. <TimeCreated SystemTime="2016-08-23T23:30:55.822473800Z" />
  7006. <EventRecordID>91</EventRecordID>
  7007. <Correlation ActivityID="{29A47941-FD96-0002-E57E-A42996FDD101}" />
  7008. <Execution ProcessID="4072" ThreadID="6780" />
  7009. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7010. <Computer>DESKTOP-D07KK79</Computer>
  7011. <Security UserID="S-1-5-18" />
  7012. </System>
  7013. <EventData>
  7014. <Data Name="ErrorCode">1168</Data>
  7015. <Data Name="PackageFullName">Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe</Data>
  7016. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7017. <Data Name="DesiredStatus">32</Data>
  7018. <Data Name="CurrentStatus">0</Data>
  7019. </EventData>
  7020. </Event>
  7021.  
  7022. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7023. Source: Microsoft-Windows-AppModel-Runtime
  7024. Date: 8/23/2016 4:30:54 PM
  7025. Event ID: 69
  7026. Task Category: None
  7027. Level: Error
  7028. Keywords: (70368744177664),Process
  7029. User: SYSTEM
  7030. Computer: DESKTOP-D07KK79
  7031. Description:
  7032. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsMaps_5.1603.1830.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7033. Event Xml:
  7034. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7035. <System>
  7036. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7037. <EventID>69</EventID>
  7038. <Version>0</Version>
  7039. <Level>2</Level>
  7040. <Task>0</Task>
  7041. <Opcode>0</Opcode>
  7042. <Keywords>0x2000400000000001</Keywords>
  7043. <TimeCreated SystemTime="2016-08-23T23:30:54.559458700Z" />
  7044. <EventRecordID>89</EventRecordID>
  7045. <Correlation ActivityID="{29A47941-FD96-0007-4F7D-A42996FDD101}" />
  7046. <Execution ProcessID="4072" ThreadID="6780" />
  7047. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7048. <Computer>DESKTOP-D07KK79</Computer>
  7049. <Security UserID="S-1-5-18" />
  7050. </System>
  7051. <EventData>
  7052. <Data Name="ErrorCode">1168</Data>
  7053. <Data Name="PackageFullName">Microsoft.WindowsMaps_5.1603.1830.0_x64__8wekyb3d8bbwe</Data>
  7054. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7055. <Data Name="DesiredStatus">32</Data>
  7056. <Data Name="CurrentStatus">0</Data>
  7057. </EventData>
  7058. </Event>
  7059.  
  7060. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7061. Source: Microsoft-Windows-AppModel-Runtime
  7062. Date: 8/23/2016 4:30:53 PM
  7063. Event ID: 69
  7064. Task Category: None
  7065. Level: Error
  7066. Keywords: (70368744177664),Process
  7067. User: SYSTEM
  7068. Computer: DESKTOP-D07KK79
  7069. Description:
  7070. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsSoundRecorder_10.1605.1622.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7071. Event Xml:
  7072. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7073. <System>
  7074. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7075. <EventID>69</EventID>
  7076. <Version>0</Version>
  7077. <Level>2</Level>
  7078. <Task>0</Task>
  7079. <Opcode>0</Opcode>
  7080. <Keywords>0x2000400000000001</Keywords>
  7081. <TimeCreated SystemTime="2016-08-23T23:30:53.326391800Z" />
  7082. <EventRecordID>87</EventRecordID>
  7083. <Correlation ActivityID="{29A47941-FD96-0007-447D-A42996FDD101}" />
  7084. <Execution ProcessID="4072" ThreadID="6776" />
  7085. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7086. <Computer>DESKTOP-D07KK79</Computer>
  7087. <Security UserID="S-1-5-18" />
  7088. </System>
  7089. <EventData>
  7090. <Data Name="ErrorCode">1168</Data>
  7091. <Data Name="PackageFullName">Microsoft.WindowsSoundRecorder_10.1605.1622.0_x64__8wekyb3d8bbwe</Data>
  7092. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7093. <Data Name="DesiredStatus">32</Data>
  7094. <Data Name="CurrentStatus">0</Data>
  7095. </EventData>
  7096. </Event>
  7097.  
  7098. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7099. Source: Microsoft-Windows-AppModel-Runtime
  7100. Date: 8/23/2016 4:30:51 PM
  7101. Event ID: 69
  7102. Task Category: None
  7103. Level: Error
  7104. Keywords: (70368744177664),Process
  7105. User: SYSTEM
  7106. Computer: DESKTOP-D07KK79
  7107. Description:
  7108. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.ZuneVideo_3.6.19281.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7109. Event Xml:
  7110. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7111. <System>
  7112. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7113. <EventID>69</EventID>
  7114. <Version>0</Version>
  7115. <Level>2</Level>
  7116. <Task>0</Task>
  7117. <Opcode>0</Opcode>
  7118. <Keywords>0x2000400000000001</Keywords>
  7119. <TimeCreated SystemTime="2016-08-23T23:30:51.954241300Z" />
  7120. <EventRecordID>85</EventRecordID>
  7121. <Correlation ActivityID="{29A47941-FD96-0002-8D7E-A42996FDD101}" />
  7122. <Execution ProcessID="4072" ThreadID="6780" />
  7123. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7124. <Computer>DESKTOP-D07KK79</Computer>
  7125. <Security UserID="S-1-5-18" />
  7126. </System>
  7127. <EventData>
  7128. <Data Name="ErrorCode">1168</Data>
  7129. <Data Name="PackageFullName">Microsoft.ZuneVideo_3.6.19281.0_x64__8wekyb3d8bbwe</Data>
  7130. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7131. <Data Name="DesiredStatus">32</Data>
  7132. <Data Name="CurrentStatus">0</Data>
  7133. </EventData>
  7134. </Event>
  7135.  
  7136. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7137. Source: Microsoft-Windows-AppModel-Runtime
  7138. Date: 8/23/2016 4:30:49 PM
  7139. Event ID: 69
  7140. Task Category: None
  7141. Level: Error
  7142. Keywords: (70368744177664),Process
  7143. User: SYSTEM
  7144. Computer: DESKTOP-D07KK79
  7145. Description:
  7146. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7147. Event Xml:
  7148. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7149. <System>
  7150. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7151. <EventID>69</EventID>
  7152. <Version>0</Version>
  7153. <Level>2</Level>
  7154. <Task>0</Task>
  7155. <Opcode>0</Opcode>
  7156. <Keywords>0x2000400000000001</Keywords>
  7157. <TimeCreated SystemTime="2016-08-23T23:30:49.983491600Z" />
  7158. <EventRecordID>83</EventRecordID>
  7159. <Correlation ActivityID="{29A47941-FD96-0002-9D7D-A42996FDD101}" />
  7160. <Execution ProcessID="4072" ThreadID="6776" />
  7161. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7162. <Computer>DESKTOP-D07KK79</Computer>
  7163. <Security UserID="S-1-5-18" />
  7164. </System>
  7165. <EventData>
  7166. <Data Name="ErrorCode">1168</Data>
  7167. <Data Name="PackageFullName">Microsoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c</Data>
  7168. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7169. <Data Name="DesiredStatus">32</Data>
  7170. <Data Name="CurrentStatus">0</Data>
  7171. </EventData>
  7172. </Event>
  7173.  
  7174. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7175. Source: Microsoft-Windows-AppModel-Runtime
  7176. Date: 8/23/2016 4:30:44 PM
  7177. Event ID: 69
  7178. Task Category: None
  7179. Level: Error
  7180. Keywords: (70368744177664),Process
  7181. User: SYSTEM
  7182. Computer: DESKTOP-D07KK79
  7183. Description:
  7184. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsAlarms_10.1605.1742.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7185. Event Xml:
  7186. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7187. <System>
  7188. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7189. <EventID>69</EventID>
  7190. <Version>0</Version>
  7191. <Level>2</Level>
  7192. <Task>0</Task>
  7193. <Opcode>0</Opcode>
  7194. <Keywords>0x2000400000000001</Keywords>
  7195. <TimeCreated SystemTime="2016-08-23T23:30:44.871974500Z" />
  7196. <EventRecordID>81</EventRecordID>
  7197. <Correlation ActivityID="{29A47941-FD96-0007-627C-A42996FDD101}" />
  7198. <Execution ProcessID="4072" ThreadID="6780" />
  7199. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7200. <Computer>DESKTOP-D07KK79</Computer>
  7201. <Security UserID="S-1-5-18" />
  7202. </System>
  7203. <EventData>
  7204. <Data Name="ErrorCode">1168</Data>
  7205. <Data Name="PackageFullName">Microsoft.WindowsAlarms_10.1605.1742.0_x64__8wekyb3d8bbwe</Data>
  7206. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7207. <Data Name="DesiredStatus">32</Data>
  7208. <Data Name="CurrentStatus">0</Data>
  7209. </EventData>
  7210. </Event>
  7211.  
  7212. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7213. Source: Microsoft-Windows-DeviceSetupManager
  7214. Date: 8/23/2016 4:30:27 PM
  7215. Event ID: 123
  7216. Task Category: None
  7217. Level: Warning
  7218. Keywords:
  7219. User: SYSTEM
  7220. Computer: DESKTOP-D07KK79
  7221. Description:
  7222. The DSM service was delayed by 37 seconds for a driver query/download/install on device 'DISPLAY\SAM0B80\5&231E9E4F&0&UID4356'
  7223. Event Xml:
  7224. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7225. <System>
  7226. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7227. <EventID>123</EventID>
  7228. <Version>0</Version>
  7229. <Level>3</Level>
  7230. <Task>0</Task>
  7231. <Opcode>0</Opcode>
  7232. <Keywords>0x4000000000000000</Keywords>
  7233. <TimeCreated SystemTime="2016-08-23T23:30:27.684315900Z" />
  7234. <EventRecordID>48</EventRecordID>
  7235. <Correlation ActivityID="{29A47941-FD96-0003-C379-A42996FDD101}" />
  7236. <Execution ProcessID="480" ThreadID="1752" />
  7237. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7238. <Computer>DESKTOP-D07KK79</Computer>
  7239. <Security UserID="S-1-5-18" />
  7240. </System>
  7241. <EventData>
  7242. <Data Name="Prop_Seconds">37</Data>
  7243. <Data Name="Prop_DeviceId">DISPLAY\SAM0B80\5&amp;231E9E4F&amp;0&amp;UID4356</Data>
  7244. </EventData>
  7245. </Event>
  7246.  
  7247. Log Name: System
  7248. Source: Microsoft-Windows-DistributedCOM
  7249. Date: 8/23/2016 4:30:05 PM
  7250. Event ID: 10016
  7251. Task Category: None
  7252. Level: Error
  7253. Keywords: Classic
  7254. User: SYSTEM
  7255. Computer: DESKTOP-D07KK79
  7256. Description:
  7257. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  7258. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  7259. and APPID
  7260. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  7261. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  7262. Event Xml:
  7263. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7264. <System>
  7265. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  7266. <EventID Qualifiers="0">10016</EventID>
  7267. <Version>0</Version>
  7268. <Level>2</Level>
  7269. <Task>0</Task>
  7270. <Opcode>0</Opcode>
  7271. <Keywords>0x8080000000000000</Keywords>
  7272. <TimeCreated SystemTime="2016-08-23T23:30:05.998161700Z" />
  7273. <EventRecordID>390</EventRecordID>
  7274. <Correlation />
  7275. <Execution ProcessID="968" ThreadID="1020" />
  7276. <Channel>System</Channel>
  7277. <Computer>DESKTOP-D07KK79</Computer>
  7278. <Security UserID="S-1-5-18" />
  7279. </System>
  7280. <EventData>
  7281. <Data Name="param1">application-specific</Data>
  7282. <Data Name="param2">Local</Data>
  7283. <Data Name="param3">Activation</Data>
  7284. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  7285. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  7286. <Data Name="param6">NT AUTHORITY</Data>
  7287. <Data Name="param7">SYSTEM</Data>
  7288. <Data Name="param8">S-1-5-18</Data>
  7289. <Data Name="param9">LocalHost (Using LRPC)</Data>
  7290. <Data Name="param10">Unavailable</Data>
  7291. <Data Name="param11">Unavailable</Data>
  7292. </EventData>
  7293. </Event>
  7294.  
  7295. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7296. Source: Microsoft-Windows-DeviceSetupManager
  7297. Date: 8/23/2016 4:29:32 PM
  7298. Event ID: 200
  7299. Task Category: None
  7300. Level: Warning
  7301. Keywords:
  7302. User: SYSTEM
  7303. Computer: DESKTOP-D07KK79
  7304. Description:
  7305. A connection to the Windows Update service could not be established.
  7306. Event Xml:
  7307. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7308. <System>
  7309. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7310. <EventID>200</EventID>
  7311. <Version>0</Version>
  7312. <Level>3</Level>
  7313. <Task>0</Task>
  7314. <Opcode>0</Opcode>
  7315. <Keywords>0x4000000000000000</Keywords>
  7316. <TimeCreated SystemTime="2016-08-23T23:29:32.815334800Z" />
  7317. <EventRecordID>44</EventRecordID>
  7318. <Correlation />
  7319. <Execution ProcessID="480" ThreadID="1704" />
  7320. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7321. <Computer>DESKTOP-D07KK79</Computer>
  7322. <Security UserID="S-1-5-18" />
  7323. </System>
  7324. <EventData>
  7325. </EventData>
  7326. </Event>
  7327.  
  7328. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7329. Source: Microsoft-Windows-DeviceSetupManager
  7330. Date: 8/23/2016 4:29:32 PM
  7331. Event ID: 202
  7332. Task Category: None
  7333. Level: Warning
  7334. Keywords:
  7335. User: SYSTEM
  7336. Computer: DESKTOP-D07KK79
  7337. Description:
  7338. The Network List Manager reports no connectivity to the internet.
  7339. Event Xml:
  7340. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7341. <System>
  7342. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7343. <EventID>202</EventID>
  7344. <Version>0</Version>
  7345. <Level>3</Level>
  7346. <Task>0</Task>
  7347. <Opcode>0</Opcode>
  7348. <Keywords>0x4000000000000000</Keywords>
  7349. <TimeCreated SystemTime="2016-08-23T23:29:32.815276300Z" />
  7350. <EventRecordID>43</EventRecordID>
  7351. <Correlation />
  7352. <Execution ProcessID="480" ThreadID="1704" />
  7353. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7354. <Computer>DESKTOP-D07KK79</Computer>
  7355. <Security UserID="S-1-5-18" />
  7356. </System>
  7357. <EventData>
  7358. </EventData>
  7359. </Event>
  7360.  
  7361. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7362. Source: Microsoft-Windows-DeviceSetupManager
  7363. Date: 8/23/2016 4:29:32 PM
  7364. Event ID: 200
  7365. Task Category: None
  7366. Level: Warning
  7367. Keywords:
  7368. User: SYSTEM
  7369. Computer: DESKTOP-D07KK79
  7370. Description:
  7371. A connection to the Windows Update service could not be established.
  7372. Event Xml:
  7373. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7374. <System>
  7375. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7376. <EventID>200</EventID>
  7377. <Version>0</Version>
  7378. <Level>3</Level>
  7379. <Task>0</Task>
  7380. <Opcode>0</Opcode>
  7381. <Keywords>0x4000000000000000</Keywords>
  7382. <TimeCreated SystemTime="2016-08-23T23:29:32.769118000Z" />
  7383. <EventRecordID>42</EventRecordID>
  7384. <Correlation />
  7385. <Execution ProcessID="480" ThreadID="1660" />
  7386. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7387. <Computer>DESKTOP-D07KK79</Computer>
  7388. <Security UserID="S-1-5-18" />
  7389. </System>
  7390. <EventData>
  7391. </EventData>
  7392. </Event>
  7393.  
  7394. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7395. Source: Microsoft-Windows-DeviceSetupManager
  7396. Date: 8/23/2016 4:29:32 PM
  7397. Event ID: 202
  7398. Task Category: None
  7399. Level: Warning
  7400. Keywords:
  7401. User: SYSTEM
  7402. Computer: DESKTOP-D07KK79
  7403. Description:
  7404. The Network List Manager reports no connectivity to the internet.
  7405. Event Xml:
  7406. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7407. <System>
  7408. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7409. <EventID>202</EventID>
  7410. <Version>0</Version>
  7411. <Level>3</Level>
  7412. <Task>0</Task>
  7413. <Opcode>0</Opcode>
  7414. <Keywords>0x4000000000000000</Keywords>
  7415. <TimeCreated SystemTime="2016-08-23T23:29:32.769046500Z" />
  7416. <EventRecordID>41</EventRecordID>
  7417. <Correlation />
  7418. <Execution ProcessID="480" ThreadID="1660" />
  7419. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7420. <Computer>DESKTOP-D07KK79</Computer>
  7421. <Security UserID="S-1-5-18" />
  7422. </System>
  7423. <EventData>
  7424. </EventData>
  7425. </Event>
  7426.  
  7427. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7428. Source: Microsoft-Windows-DeviceSetupManager
  7429. Date: 8/23/2016 4:29:32 PM
  7430. Event ID: 200
  7431. Task Category: None
  7432. Level: Warning
  7433. Keywords:
  7434. User: SYSTEM
  7435. Computer: DESKTOP-D07KK79
  7436. Description:
  7437. A connection to the Windows Update service could not be established.
  7438. Event Xml:
  7439. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7440. <System>
  7441. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7442. <EventID>200</EventID>
  7443. <Version>0</Version>
  7444. <Level>3</Level>
  7445. <Task>0</Task>
  7446. <Opcode>0</Opcode>
  7447. <Keywords>0x4000000000000000</Keywords>
  7448. <TimeCreated SystemTime="2016-08-23T23:29:32.768908400Z" />
  7449. <EventRecordID>40</EventRecordID>
  7450. <Correlation />
  7451. <Execution ProcessID="480" ThreadID="1640" />
  7452. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7453. <Computer>DESKTOP-D07KK79</Computer>
  7454. <Security UserID="S-1-5-18" />
  7455. </System>
  7456. <EventData>
  7457. </EventData>
  7458. </Event>
  7459.  
  7460. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7461. Source: Microsoft-Windows-DeviceSetupManager
  7462. Date: 8/23/2016 4:29:32 PM
  7463. Event ID: 202
  7464. Task Category: None
  7465. Level: Warning
  7466. Keywords:
  7467. User: SYSTEM
  7468. Computer: DESKTOP-D07KK79
  7469. Description:
  7470. The Network List Manager reports no connectivity to the internet.
  7471. Event Xml:
  7472. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7473. <System>
  7474. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7475. <EventID>202</EventID>
  7476. <Version>0</Version>
  7477. <Level>3</Level>
  7478. <Task>0</Task>
  7479. <Opcode>0</Opcode>
  7480. <Keywords>0x4000000000000000</Keywords>
  7481. <TimeCreated SystemTime="2016-08-23T23:29:32.768832400Z" />
  7482. <EventRecordID>39</EventRecordID>
  7483. <Correlation />
  7484. <Execution ProcessID="480" ThreadID="1640" />
  7485. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7486. <Computer>DESKTOP-D07KK79</Computer>
  7487. <Security UserID="S-1-5-18" />
  7488. </System>
  7489. <EventData>
  7490. </EventData>
  7491. </Event>
  7492.  
  7493. Log Name: System
  7494. Source: Microsoft-Windows-Kernel-PnP
  7495. Date: 8/23/2016 4:29:19 PM
  7496. Event ID: 219
  7497. Task Category: (212)
  7498. Level: Warning
  7499. Keywords:
  7500. User: SYSTEM
  7501. Computer: DESKTOP-D07KK79
  7502. Description:
  7503. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  7504. Event Xml:
  7505. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7506. <System>
  7507. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  7508. <EventID>219</EventID>
  7509. <Version>0</Version>
  7510. <Level>3</Level>
  7511. <Task>212</Task>
  7512. <Opcode>0</Opcode>
  7513. <Keywords>0x8000000000000000</Keywords>
  7514. <TimeCreated SystemTime="2016-08-23T23:29:19.022326600Z" />
  7515. <EventRecordID>365</EventRecordID>
  7516. <Correlation />
  7517. <Execution ProcessID="4" ThreadID="384" />
  7518. <Channel>System</Channel>
  7519. <Computer>DESKTOP-D07KK79</Computer>
  7520. <Security UserID="S-1-5-18" />
  7521. </System>
  7522. <EventData>
  7523. <Data Name="DriverNameLength">24</Data>
  7524. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  7525. <Data Name="Status">3221226341</Data>
  7526. <Data Name="FailureNameLength">14</Data>
  7527. <Data Name="FailureName">\Driver\WUDFRd</Data>
  7528. <Data Name="Version">0</Data>
  7529. </EventData>
  7530. </Event>
  7531.  
  7532. Log Name: Application
  7533. Source: Microsoft-Windows-Perflib
  7534. Date: 8/23/2016 4:25:31 PM
  7535. Event ID: 1023
  7536. Task Category: None
  7537. Level: Error
  7538. Keywords: Classic
  7539. User: N/A
  7540. Computer: DESKTOP-D07KK79
  7541. Description:
  7542. Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code.
  7543. Event Xml:
  7544. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7545. <System>
  7546. <Provider Name="Microsoft-Windows-Perflib" Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
  7547. <EventID Qualifiers="49152">1023</EventID>
  7548. <Version>0</Version>
  7549. <Level>2</Level>
  7550. <Task>0</Task>
  7551. <Opcode>0</Opcode>
  7552. <Keywords>0x80000000000000</Keywords>
  7553. <TimeCreated SystemTime="2016-08-23T23:25:31.441676800Z" />
  7554. <EventRecordID>207</EventRecordID>
  7555. <Correlation />
  7556. <Execution ProcessID="0" ThreadID="0" />
  7557. <Channel>Application</Channel>
  7558. <Computer>DESKTOP-D07KK79</Computer>
  7559. <Security />
  7560. </System>
  7561. <UserData>
  7562. <EventXML xmlns="Perflib">
  7563. <param1>rdyboost</param1>
  7564. <binaryDataSize>4</binaryDataSize>
  7565. <binaryData>7E000000</binaryData>
  7566. </EventXML>
  7567. </UserData>
  7568. </Event>
  7569.  
  7570. Log Name: Application
  7571. Source: Microsoft-Windows-Perflib
  7572. Date: 8/23/2016 4:25:31 PM
  7573. Event ID: 1008
  7574. Task Category: None
  7575. Level: Error
  7576. Keywords: Classic
  7577. User: N/A
  7578. Computer: DESKTOP-D07KK79
  7579. Description:
  7580. The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
  7581. Event Xml:
  7582. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7583. <System>
  7584. <Provider Name="Microsoft-Windows-Perflib" Guid="{13B197BD-7CEE-4B4E-8DD0-59314CE374CE}" EventSourceName="Perflib" />
  7585. <EventID Qualifiers="49152">1008</EventID>
  7586. <Version>0</Version>
  7587. <Level>2</Level>
  7588. <Task>0</Task>
  7589. <Opcode>0</Opcode>
  7590. <Keywords>0x80000000000000</Keywords>
  7591. <TimeCreated SystemTime="2016-08-23T23:25:31.138650100Z" />
  7592. <EventRecordID>206</EventRecordID>
  7593. <Correlation />
  7594. <Execution ProcessID="0" ThreadID="0" />
  7595. <Channel>Application</Channel>
  7596. <Computer>DESKTOP-D07KK79</Computer>
  7597. <Security />
  7598. </System>
  7599. <UserData>
  7600. <EventXML xmlns="Perflib">
  7601. <param1>BITS</param1>
  7602. <param2>C:\Windows\System32\bitsperf.dll</param2>
  7603. <binaryDataSize>4</binaryDataSize>
  7604. <binaryData>02000000</binaryData>
  7605. </EventXML>
  7606. </UserData>
  7607. </Event>
  7608.  
  7609. Log Name: System
  7610. Source: Microsoft-Windows-Kernel-PnP
  7611. Date: 8/23/2016 4:25:29 PM
  7612. Event ID: 225
  7613. Task Category: (223)
  7614. Level: Warning
  7615. Keywords:
  7616. User: SYSTEM
  7617. Computer: DESKTOP-D07KK79
  7618. Description:
  7619. The application \Device\CdRom0\Bin\Select.exe with process id 7064 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C82&SUBSYS_85341043&REV_00\3&11583659&0&FA.
  7620. Event Xml:
  7621. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7622. <System>
  7623. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  7624. <EventID>225</EventID>
  7625. <Version>0</Version>
  7626. <Level>3</Level>
  7627. <Task>223</Task>
  7628. <Opcode>0</Opcode>
  7629. <Keywords>0x8000000000000000</Keywords>
  7630. <TimeCreated SystemTime="2016-08-23T23:25:29.596867200Z" />
  7631. <EventRecordID>334</EventRecordID>
  7632. <Correlation />
  7633. <Execution ProcessID="4" ThreadID="4080" />
  7634. <Channel>System</Channel>
  7635. <Computer>DESKTOP-D07KK79</Computer>
  7636. <Security UserID="S-1-5-18" />
  7637. </System>
  7638. <EventData>
  7639. <Data Name="ProcessId">7064</Data>
  7640. <Data Name="ProcessNameLength">29</Data>
  7641. <Data Name="ProcessName">\Device\CdRom0\Bin\Select.exe</Data>
  7642. <Data Name="DeviceInstanceLength">60</Data>
  7643. <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_8C82&amp;SUBSYS_85341043&amp;REV_00\3&amp;11583659&amp;0&amp;FA</Data>
  7644. </EventData>
  7645. </Event>
  7646.  
  7647. Log Name: System
  7648. Source: Microsoft-Windows-Kernel-PnP
  7649. Date: 8/23/2016 4:25:29 PM
  7650. Event ID: 225
  7651. Task Category: (223)
  7652. Level: Warning
  7653. Keywords:
  7654. User: SYSTEM
  7655. Computer: DESKTOP-D07KK79
  7656. Description:
  7657. The application \Device\CdRom0\Bin\AsusInstAll\InstAll.exe with process id 6600 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C82&SUBSYS_85341043&REV_00\3&11583659&0&FA.
  7658. Event Xml:
  7659. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7660. <System>
  7661. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  7662. <EventID>225</EventID>
  7663. <Version>0</Version>
  7664. <Level>3</Level>
  7665. <Task>223</Task>
  7666. <Opcode>0</Opcode>
  7667. <Keywords>0x8000000000000000</Keywords>
  7668. <TimeCreated SystemTime="2016-08-23T23:25:29.596866400Z" />
  7669. <EventRecordID>333</EventRecordID>
  7670. <Correlation />
  7671. <Execution ProcessID="4" ThreadID="4080" />
  7672. <Channel>System</Channel>
  7673. <Computer>DESKTOP-D07KK79</Computer>
  7674. <Security UserID="S-1-5-18" />
  7675. </System>
  7676. <EventData>
  7677. <Data Name="ProcessId">6600</Data>
  7678. <Data Name="ProcessNameLength">42</Data>
  7679. <Data Name="ProcessName">\Device\CdRom0\Bin\AsusInstAll\InstAll.exe</Data>
  7680. <Data Name="DeviceInstanceLength">60</Data>
  7681. <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_8C82&amp;SUBSYS_85341043&amp;REV_00\3&amp;11583659&amp;0&amp;FA</Data>
  7682. </EventData>
  7683. </Event>
  7684.  
  7685. Log Name: System
  7686. Source: Microsoft-Windows-Kernel-PnP
  7687. Date: 8/23/2016 4:25:29 PM
  7688. Event ID: 225
  7689. Task Category: (223)
  7690. Level: Warning
  7691. Keywords:
  7692. User: SYSTEM
  7693. Computer: DESKTOP-D07KK79
  7694. Description:
  7695. The application \Device\CdRom0\Drivers\RAID\IRST\Install\Driver\SetupRST.exe with process id 6068 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C82&SUBSYS_85341043&REV_00\3&11583659&0&FA.
  7696. Event Xml:
  7697. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7698. <System>
  7699. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  7700. <EventID>225</EventID>
  7701. <Version>0</Version>
  7702. <Level>3</Level>
  7703. <Task>223</Task>
  7704. <Opcode>0</Opcode>
  7705. <Keywords>0x8000000000000000</Keywords>
  7706. <TimeCreated SystemTime="2016-08-23T23:25:29.596865400Z" />
  7707. <EventRecordID>332</EventRecordID>
  7708. <Correlation />
  7709. <Execution ProcessID="4" ThreadID="4080" />
  7710. <Channel>System</Channel>
  7711. <Computer>DESKTOP-D07KK79</Computer>
  7712. <Security UserID="S-1-5-18" />
  7713. </System>
  7714. <EventData>
  7715. <Data Name="ProcessId">6068</Data>
  7716. <Data Name="ProcessNameLength">60</Data>
  7717. <Data Name="ProcessName">\Device\CdRom0\Drivers\RAID\IRST\Install\Driver\SetupRST.exe</Data>
  7718. <Data Name="DeviceInstanceLength">60</Data>
  7719. <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_8C82&amp;SUBSYS_85341043&amp;REV_00\3&amp;11583659&amp;0&amp;FA</Data>
  7720. </EventData>
  7721. </Event>
  7722.  
  7723. Log Name: System
  7724. Source: e1dexpress
  7725. Date: 8/23/2016 4:24:47 PM
  7726. Event ID: 27
  7727. Task Category: None
  7728. Level: Warning
  7729. Keywords: Classic
  7730. User: N/A
  7731. Computer: DESKTOP-D07KK79
  7732. Description:
  7733. Intel(R) Ethernet Connection (2) I218-V
  7734. Network link is disconnected.
  7735.  
  7736. Event Xml:
  7737. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7738. <System>
  7739. <Provider Name="e1dexpress" />
  7740. <EventID Qualifiers="40964">27</EventID>
  7741. <Level>3</Level>
  7742. <Task>0</Task>
  7743. <Keywords>0x80000000000000</Keywords>
  7744. <TimeCreated SystemTime="2016-08-23T23:24:47.819867400Z" />
  7745. <EventRecordID>329</EventRecordID>
  7746. <Channel>System</Channel>
  7747. <Computer>DESKTOP-D07KK79</Computer>
  7748. <Security />
  7749. </System>
  7750. <EventData>
  7751. <Data>
  7752. </Data>
  7753. <Data>Intel(R) Ethernet Connection (2) I218-V</Data>
  7754. <Binary>0000040002003000000000001B0004A00000000000000000000000000000000000000000000000001B0004A0</Binary>
  7755. </EventData>
  7756. </Event>
  7757.  
  7758. Log Name: System
  7759. Source: e1iexpress
  7760. Date: 8/23/2016 4:24:40 PM
  7761. Event ID: 27
  7762. Task Category: None
  7763. Level: Warning
  7764. Keywords: Classic
  7765. User: N/A
  7766. Computer: DESKTOP-D07KK79
  7767. Description:
  7768. Intel(R) Ethernet Connection (2) I218-V
  7769. Network link is disconnected.
  7770.  
  7771. Event Xml:
  7772. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7773. <System>
  7774. <Provider Name="e1iexpress" />
  7775. <EventID Qualifiers="40964">27</EventID>
  7776. <Level>3</Level>
  7777. <Task>0</Task>
  7778. <Keywords>0x80000000000000</Keywords>
  7779. <TimeCreated SystemTime="2016-08-23T23:24:40.249411800Z" />
  7780. <EventRecordID>324</EventRecordID>
  7781. <Channel>System</Channel>
  7782. <Computer>DESKTOP-D07KK79</Computer>
  7783. <Security />
  7784. </System>
  7785. <EventData>
  7786. <Data>
  7787. </Data>
  7788. <Data>Intel(R) Ethernet Connection (2) I218-V</Data>
  7789. <Binary>0000040002003000000000001B0004A00000000000000000000000000000000000000000000000001B0004A0</Binary>
  7790. </EventData>
  7791. </Event>
  7792.  
  7793. Log Name: Application
  7794. Source: Microsoft-Windows-CAPI2
  7795. Date: 8/23/2016 4:24:30 PM
  7796. Event ID: 513
  7797. Task Category: None
  7798. Level: Error
  7799. Keywords: Classic
  7800. User: N/A
  7801. Computer: DESKTOP-D07KK79
  7802. Description:
  7803. Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
  7804.  
  7805. Details:
  7806. AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
  7807.  
  7808. System Error:
  7809. Access is denied.
  7810. .
  7811. Event Xml:
  7812. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7813. <System>
  7814. <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />
  7815. <EventID Qualifiers="0">513</EventID>
  7816. <Version>0</Version>
  7817. <Level>2</Level>
  7818. <Task>0</Task>
  7819. <Opcode>0</Opcode>
  7820. <Keywords>0x8080000000000000</Keywords>
  7821. <TimeCreated SystemTime="2016-08-23T23:24:30.001489300Z" />
  7822. <EventRecordID>177</EventRecordID>
  7823. <Correlation />
  7824. <Execution ProcessID="1408" ThreadID="1444" />
  7825. <Channel>Application</Channel>
  7826. <Computer>DESKTOP-D07KK79</Computer>
  7827. <Security />
  7828. </System>
  7829. <EventData>
  7830. <Data>
  7831.  
  7832. Details:
  7833. AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
  7834.  
  7835. System Error:
  7836. Access is denied.
  7837. </Data>
  7838. </EventData>
  7839. </Event>
  7840.  
  7841. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  7842. Source: Microsoft-Windows-DeviceSetupManager
  7843. Date: 8/23/2016 4:20:38 PM
  7844. Event ID: 123
  7845. Task Category: None
  7846. Level: Warning
  7847. Keywords:
  7848. User: SYSTEM
  7849. Computer: DESKTOP-D07KK79
  7850. Description:
  7851. The DSM service was delayed by 151 seconds for a driver query/download/install on device 'PCI\VEN_10DE&DEV_17C8&SUBSYS_85491043&REV_A1\4&3834D97&0&0008'
  7852. Event Xml:
  7853. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7854. <System>
  7855. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  7856. <EventID>123</EventID>
  7857. <Version>0</Version>
  7858. <Level>3</Level>
  7859. <Task>0</Task>
  7860. <Opcode>0</Opcode>
  7861. <Keywords>0x4000000000000000</Keywords>
  7862. <TimeCreated SystemTime="2016-08-23T23:20:38.879977600Z" />
  7863. <EventRecordID>16</EventRecordID>
  7864. <Correlation ActivityID="{3FC22F77-FD94-0006-9530-C23F94FDD101}" />
  7865. <Execution ProcessID="1012" ThreadID="1528" />
  7866. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  7867. <Computer>DESKTOP-D07KK79</Computer>
  7868. <Security UserID="S-1-5-18" />
  7869. </System>
  7870. <EventData>
  7871. <Data Name="Prop_Seconds">151</Data>
  7872. <Data Name="Prop_DeviceId">PCI\VEN_10DE&amp;DEV_17C8&amp;SUBSYS_85491043&amp;REV_A1\4&amp;3834D97&amp;0&amp;0008</Data>
  7873. </EventData>
  7874. </Event>
  7875.  
  7876. Log Name: Application
  7877. Source: Microsoft-Windows-Search
  7878. Date: 8/23/2016 4:20:36 PM
  7879. Event ID: 3104
  7880. Task Category: Gatherer
  7881. Level: Error
  7882. Keywords: Classic
  7883. User: N/A
  7884. Computer: DESKTOP-D07KK79
  7885. Description:
  7886. Enumerating user sessions to generate filter pools failed.
  7887.  
  7888. Details:
  7889. (HRESULT : 0x80040210) (0x80040210)
  7890.  
  7891. Event Xml:
  7892. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7893. <System>
  7894. <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
  7895. <EventID Qualifiers="49152">3104</EventID>
  7896. <Version>0</Version>
  7897. <Level>2</Level>
  7898. <Task>3</Task>
  7899. <Opcode>0</Opcode>
  7900. <Keywords>0x80000000000000</Keywords>
  7901. <TimeCreated SystemTime="2016-08-23T23:20:36.213818000Z" />
  7902. <EventRecordID>106</EventRecordID>
  7903. <Correlation />
  7904. <Execution ProcessID="0" ThreadID="0" />
  7905. <Channel>Application</Channel>
  7906. <Computer>DESKTOP-D07KK79</Computer>
  7907. <Security />
  7908. </System>
  7909. <EventData>
  7910. <Data>
  7911.  
  7912. Details:
  7913. (HRESULT : 0x80040210) (0x80040210)
  7914. </Data>
  7915. </EventData>
  7916. </Event>
  7917.  
  7918. Log Name: Application
  7919. Source: Microsoft-Windows-Search
  7920. Date: 8/23/2016 4:20:36 PM
  7921. Event ID: 3104
  7922. Task Category: Gatherer
  7923. Level: Error
  7924. Keywords: Classic
  7925. User: N/A
  7926. Computer: DESKTOP-D07KK79
  7927. Description:
  7928. Enumerating user sessions to generate filter pools failed.
  7929.  
  7930. Details:
  7931. (HRESULT : 0x80040210) (0x80040210)
  7932.  
  7933. Event Xml:
  7934. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7935. <System>
  7936. <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
  7937. <EventID Qualifiers="49152">3104</EventID>
  7938. <Version>0</Version>
  7939. <Level>2</Level>
  7940. <Task>3</Task>
  7941. <Opcode>0</Opcode>
  7942. <Keywords>0x80000000000000</Keywords>
  7943. <TimeCreated SystemTime="2016-08-23T23:20:36.212818200Z" />
  7944. <EventRecordID>105</EventRecordID>
  7945. <Correlation />
  7946. <Execution ProcessID="0" ThreadID="0" />
  7947. <Channel>Application</Channel>
  7948. <Computer>DESKTOP-D07KK79</Computer>
  7949. <Security />
  7950. </System>
  7951. <EventData>
  7952. <Data>
  7953.  
  7954. Details:
  7955. (HRESULT : 0x80040210) (0x80040210)
  7956. </Data>
  7957. </EventData>
  7958. </Event>
  7959.  
  7960. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7961. Source: Microsoft-Windows-AppModel-Runtime
  7962. Date: 8/23/2016 4:20:18 PM
  7963. Event ID: 69
  7964. Task Category: None
  7965. Level: Error
  7966. Keywords: (70368744177664),Process
  7967. User: SYSTEM
  7968. Computer: DESKTOP-D07KK79
  7969. Description:
  7970. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.ZuneMusic_3.6.19261.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  7971. Event Xml:
  7972. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  7973. <System>
  7974. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  7975. <EventID>69</EventID>
  7976. <Version>0</Version>
  7977. <Level>2</Level>
  7978. <Task>0</Task>
  7979. <Opcode>0</Opcode>
  7980. <Keywords>0x2000400000000001</Keywords>
  7981. <TimeCreated SystemTime="2016-08-23T23:20:18.179388900Z" />
  7982. <EventRecordID>79</EventRecordID>
  7983. <Correlation ActivityID="{3FC22F77-FD94-0000-4F39-C23F94FDD101}" />
  7984. <Execution ProcessID="968" ThreadID="4980" />
  7985. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  7986. <Computer>DESKTOP-D07KK79</Computer>
  7987. <Security UserID="S-1-5-18" />
  7988. </System>
  7989. <EventData>
  7990. <Data Name="ErrorCode">1168</Data>
  7991. <Data Name="PackageFullName">Microsoft.ZuneMusic_3.6.19261.0_x64__8wekyb3d8bbwe</Data>
  7992. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  7993. <Data Name="DesiredStatus">32</Data>
  7994. <Data Name="CurrentStatus">0</Data>
  7995. </EventData>
  7996. </Event>
  7997.  
  7998. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  7999. Source: Microsoft-Windows-AppModel-Runtime
  8000. Date: 8/23/2016 4:20:17 PM
  8001. Event ID: 69
  8002. Task Category: None
  8003. Level: Error
  8004. Keywords: (70368744177664),Process
  8005. User: SYSTEM
  8006. Computer: DESKTOP-D07KK79
  8007. Description:
  8008. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.XboxIdentityProvider_11.18.16009.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8009. Event Xml:
  8010. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8011. <System>
  8012. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8013. <EventID>69</EventID>
  8014. <Version>0</Version>
  8015. <Level>2</Level>
  8016. <Task>0</Task>
  8017. <Opcode>0</Opcode>
  8018. <Keywords>0x2000400000000001</Keywords>
  8019. <TimeCreated SystemTime="2016-08-23T23:20:17.671763600Z" />
  8020. <EventRecordID>77</EventRecordID>
  8021. <Correlation ActivityID="{3FC22F77-FD94-0007-7035-C23F94FDD101}" />
  8022. <Execution ProcessID="968" ThreadID="4984" />
  8023. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8024. <Computer>DESKTOP-D07KK79</Computer>
  8025. <Security UserID="S-1-5-18" />
  8026. </System>
  8027. <EventData>
  8028. <Data Name="ErrorCode">1168</Data>
  8029. <Data Name="PackageFullName">Microsoft.XboxIdentityProvider_11.18.16009.0_x64__8wekyb3d8bbwe</Data>
  8030. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8031. <Data Name="DesiredStatus">32</Data>
  8032. <Data Name="CurrentStatus">0</Data>
  8033. </EventData>
  8034. </Event>
  8035.  
  8036. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8037. Source: Microsoft-Windows-AppModel-Runtime
  8038. Date: 8/23/2016 4:20:16 PM
  8039. Event ID: 69
  8040. Task Category: None
  8041. Level: Error
  8042. Keywords: (70368744177664),Process
  8043. User: SYSTEM
  8044. Computer: DESKTOP-D07KK79
  8045. Description:
  8046. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.XboxApp_15.18.23005.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8047. Event Xml:
  8048. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8049. <System>
  8050. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8051. <EventID>69</EventID>
  8052. <Version>0</Version>
  8053. <Level>2</Level>
  8054. <Task>0</Task>
  8055. <Opcode>0</Opcode>
  8056. <Keywords>0x2000400000000001</Keywords>
  8057. <TimeCreated SystemTime="2016-08-23T23:20:16.126404800Z" />
  8058. <EventRecordID>75</EventRecordID>
  8059. <Correlation ActivityID="{3FC22F77-FD94-0000-0439-C23F94FDD101}" />
  8060. <Execution ProcessID="968" ThreadID="4992" />
  8061. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8062. <Computer>DESKTOP-D07KK79</Computer>
  8063. <Security UserID="S-1-5-18" />
  8064. </System>
  8065. <EventData>
  8066. <Data Name="ErrorCode">1168</Data>
  8067. <Data Name="PackageFullName">Microsoft.XboxApp_15.18.23005.0_x64__8wekyb3d8bbwe</Data>
  8068. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8069. <Data Name="DesiredStatus">32</Data>
  8070. <Data Name="CurrentStatus">0</Data>
  8071. </EventData>
  8072. </Event>
  8073.  
  8074. Log Name: Application
  8075. Source: Application Error
  8076. Date: 8/23/2016 4:20:14 PM
  8077. Event ID: 1000
  8078. Task Category: (100)
  8079. Level: Error
  8080. Keywords: Classic
  8081. User: N/A
  8082. Computer: DESKTOP-D07KK79
  8083. Description:
  8084. Faulting application name: SearchUI.exe, version: 10.0.14393.82, time stamp: 0x57a55960
  8085. Faulting module name: CSGSuggestLib.dll, version: 0.0.0.0, time stamp: 0x57a557b2
  8086. Exception code: 0xc0000005
  8087. Fault offset: 0x0000000000036bc7
  8088. Faulting process id: 0xcd0
  8089. Faulting application start time: 0x01d1fd94d9e6cfc8
  8090. Faulting application path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
  8091. Faulting module path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
  8092. Report Id: 80ea532f-2f89-4808-9386-e2f612ac8345
  8093. Faulting package full name: Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy
  8094. Faulting package-relative application ID: CortanaUI
  8095. Event Xml:
  8096. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8097. <System>
  8098. <Provider Name="Application Error" />
  8099. <EventID Qualifiers="0">1000</EventID>
  8100. <Level>2</Level>
  8101. <Task>100</Task>
  8102. <Keywords>0x80000000000000</Keywords>
  8103. <TimeCreated SystemTime="2016-08-23T23:20:14.437916600Z" />
  8104. <EventRecordID>103</EventRecordID>
  8105. <Channel>Application</Channel>
  8106. <Computer>DESKTOP-D07KK79</Computer>
  8107. <Security />
  8108. </System>
  8109. <EventData>
  8110. <Data>SearchUI.exe</Data>
  8111. <Data>10.0.14393.82</Data>
  8112. <Data>57a55960</Data>
  8113. <Data>CSGSuggestLib.dll</Data>
  8114. <Data>0.0.0.0</Data>
  8115. <Data>57a557b2</Data>
  8116. <Data>c0000005</Data>
  8117. <Data>0000000000036bc7</Data>
  8118. <Data>cd0</Data>
  8119. <Data>01d1fd94d9e6cfc8</Data>
  8120. <Data>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Data>
  8121. <Data>C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll</Data>
  8122. <Data>80ea532f-2f89-4808-9386-e2f612ac8345</Data>
  8123. <Data>Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy</Data>
  8124. <Data>CortanaUI</Data>
  8125. </EventData>
  8126. </Event>
  8127.  
  8128. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8129. Source: Microsoft-Windows-AppModel-Runtime
  8130. Date: 8/23/2016 4:20:14 PM
  8131. Event ID: 69
  8132. Task Category: None
  8133. Level: Error
  8134. Keywords: (70368744177664),Process
  8135. User: SYSTEM
  8136. Computer: DESKTOP-D07KK79
  8137. Description:
  8138. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsStore_11606.1001.39.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8139. Event Xml:
  8140. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8141. <System>
  8142. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8143. <EventID>69</EventID>
  8144. <Version>0</Version>
  8145. <Level>2</Level>
  8146. <Task>0</Task>
  8147. <Opcode>0</Opcode>
  8148. <Keywords>0x2000400000000001</Keywords>
  8149. <TimeCreated SystemTime="2016-08-23T23:20:14.433106900Z" />
  8150. <EventRecordID>73</EventRecordID>
  8151. <Correlation ActivityID="{3FC22F77-FD94-0007-E034-C23F94FDD101}" />
  8152. <Execution ProcessID="968" ThreadID="4984" />
  8153. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8154. <Computer>DESKTOP-D07KK79</Computer>
  8155. <Security UserID="S-1-5-18" />
  8156. </System>
  8157. <EventData>
  8158. <Data Name="ErrorCode">1168</Data>
  8159. <Data Name="PackageFullName">Microsoft.WindowsStore_11606.1001.39.0_x64__8wekyb3d8bbwe</Data>
  8160. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8161. <Data Name="DesiredStatus">32</Data>
  8162. <Data Name="CurrentStatus">0</Data>
  8163. </EventData>
  8164. </Event>
  8165.  
  8166. Log Name: System
  8167. Source: Microsoft-Windows-DistributedCOM
  8168. Date: 8/23/2016 4:20:08 PM
  8169. Event ID: 10016
  8170. Task Category: None
  8171. Level: Error
  8172. Keywords: Classic
  8173. User: SYSTEM
  8174. Computer: DESKTOP-D07KK79
  8175. Description:
  8176. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  8177. {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
  8178. and APPID
  8179. {F72671A9-012C-4725-9D2F-2A4D32D65169}
  8180. to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  8181. Event Xml:
  8182. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8183. <System>
  8184. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  8185. <EventID Qualifiers="0">10016</EventID>
  8186. <Version>0</Version>
  8187. <Level>2</Level>
  8188. <Task>0</Task>
  8189. <Opcode>0</Opcode>
  8190. <Keywords>0x8080000000000000</Keywords>
  8191. <TimeCreated SystemTime="2016-08-23T23:20:08.492397400Z" />
  8192. <EventRecordID>272</EventRecordID>
  8193. <Correlation />
  8194. <Execution ProcessID="860" ThreadID="4016" />
  8195. <Channel>System</Channel>
  8196. <Computer>DESKTOP-D07KK79</Computer>
  8197. <Security UserID="S-1-5-18" />
  8198. </System>
  8199. <EventData>
  8200. <Data Name="param1">application-specific</Data>
  8201. <Data Name="param2">Local</Data>
  8202. <Data Name="param3">Activation</Data>
  8203. <Data Name="param4">{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}</Data>
  8204. <Data Name="param5">{F72671A9-012C-4725-9D2F-2A4D32D65169}</Data>
  8205. <Data Name="param6">NT AUTHORITY</Data>
  8206. <Data Name="param7">SYSTEM</Data>
  8207. <Data Name="param8">S-1-5-18</Data>
  8208. <Data Name="param9">LocalHost (Using LRPC)</Data>
  8209. <Data Name="param10">Unavailable</Data>
  8210. <Data Name="param11">Unavailable</Data>
  8211. </EventData>
  8212. </Event>
  8213.  
  8214. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8215. Source: Microsoft-Windows-AppModel-Runtime
  8216. Date: 8/23/2016 4:20:07 PM
  8217. Event ID: 69
  8218. Task Category: None
  8219. Level: Error
  8220. Keywords: (70368744177664),Process
  8221. User: SYSTEM
  8222. Computer: DESKTOP-D07KK79
  8223. Description:
  8224. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsFeedbackHub_1.3.1741.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8225. Event Xml:
  8226. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8227. <System>
  8228. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8229. <EventID>69</EventID>
  8230. <Version>0</Version>
  8231. <Level>2</Level>
  8232. <Task>0</Task>
  8233. <Opcode>0</Opcode>
  8234. <Keywords>0x2000400000000001</Keywords>
  8235. <TimeCreated SystemTime="2016-08-23T23:20:07.973860200Z" />
  8236. <EventRecordID>71</EventRecordID>
  8237. <Correlation ActivityID="{3FC22F77-FD94-0000-E236-C23F94FDD101}" />
  8238. <Execution ProcessID="968" ThreadID="4996" />
  8239. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8240. <Computer>DESKTOP-D07KK79</Computer>
  8241. <Security UserID="S-1-5-18" />
  8242. </System>
  8243. <EventData>
  8244. <Data Name="ErrorCode">1168</Data>
  8245. <Data Name="PackageFullName">Microsoft.WindowsFeedbackHub_1.3.1741.0_x64__8wekyb3d8bbwe</Data>
  8246. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8247. <Data Name="DesiredStatus">32</Data>
  8248. <Data Name="CurrentStatus">0</Data>
  8249. </EventData>
  8250. </Event>
  8251.  
  8252. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8253. Source: Microsoft-Windows-AppModel-Runtime
  8254. Date: 8/23/2016 4:20:06 PM
  8255. Event ID: 69
  8256. Task Category: None
  8257. Level: Error
  8258. Keywords: (70368744177664),Process
  8259. User: SYSTEM
  8260. Computer: DESKTOP-D07KK79
  8261. Description:
  8262. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.WindowsCamera_2016.404.190.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8263. Event Xml:
  8264. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8265. <System>
  8266. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8267. <EventID>69</EventID>
  8268. <Version>0</Version>
  8269. <Level>2</Level>
  8270. <Task>0</Task>
  8271. <Opcode>0</Opcode>
  8272. <Keywords>0x2000400000000001</Keywords>
  8273. <TimeCreated SystemTime="2016-08-23T23:20:06.304159100Z" />
  8274. <EventRecordID>69</EventRecordID>
  8275. <Correlation ActivityID="{3FC22F77-FD94-0002-9733-C23F94FDD101}" />
  8276. <Execution ProcessID="968" ThreadID="4980" />
  8277. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8278. <Computer>DESKTOP-D07KK79</Computer>
  8279. <Security UserID="S-1-5-18" />
  8280. </System>
  8281. <EventData>
  8282. <Data Name="ErrorCode">1168</Data>
  8283. <Data Name="PackageFullName">Microsoft.WindowsCamera_2016.404.190.0_x64__8wekyb3d8bbwe</Data>
  8284. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8285. <Data Name="DesiredStatus">32</Data>
  8286. <Data Name="CurrentStatus">0</Data>
  8287. </EventData>
  8288. </Event>
  8289.  
  8290. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8291. Source: Microsoft-Windows-AppModel-Runtime
  8292. Date: 8/23/2016 4:20:02 PM
  8293. Event ID: 69
  8294. Task Category: None
  8295. Level: Error
  8296. Keywords: (70368744177664),Process
  8297. User: SYSTEM
  8298. Computer: DESKTOP-D07KK79
  8299. Description:
  8300. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.Photos_16.511.8780.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8301. Event Xml:
  8302. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8303. <System>
  8304. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8305. <EventID>69</EventID>
  8306. <Version>0</Version>
  8307. <Level>2</Level>
  8308. <Task>0</Task>
  8309. <Opcode>0</Opcode>
  8310. <Keywords>0x2000400000000001</Keywords>
  8311. <TimeCreated SystemTime="2016-08-23T23:20:02.566919300Z" />
  8312. <EventRecordID>67</EventRecordID>
  8313. <Correlation ActivityID="{3FC22F77-FD94-0005-7A33-C23F94FDD101}" />
  8314. <Execution ProcessID="968" ThreadID="4992" />
  8315. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8316. <Computer>DESKTOP-D07KK79</Computer>
  8317. <Security UserID="S-1-5-18" />
  8318. </System>
  8319. <EventData>
  8320. <Data Name="ErrorCode">1168</Data>
  8321. <Data Name="PackageFullName">Microsoft.Windows.Photos_16.511.8780.0_x64__8wekyb3d8bbwe</Data>
  8322. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8323. <Data Name="DesiredStatus">32</Data>
  8324. <Data Name="CurrentStatus">0</Data>
  8325. </EventData>
  8326. </Event>
  8327.  
  8328. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8329. Source: Microsoft-Windows-AppModel-Runtime
  8330. Date: 8/23/2016 4:20:00 PM
  8331. Event ID: 69
  8332. Task Category: None
  8333. Level: Error
  8334. Keywords: (70368744177664),Process
  8335. User: SYSTEM
  8336. Computer: DESKTOP-D07KK79
  8337. Description:
  8338. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Getstarted_3.11.3.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8339. Event Xml:
  8340. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8341. <System>
  8342. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8343. <EventID>69</EventID>
  8344. <Version>0</Version>
  8345. <Level>2</Level>
  8346. <Task>0</Task>
  8347. <Opcode>0</Opcode>
  8348. <Keywords>0x2000400000000001</Keywords>
  8349. <TimeCreated SystemTime="2016-08-23T23:20:00.878178700Z" />
  8350. <EventRecordID>65</EventRecordID>
  8351. <Correlation ActivityID="{3FC22F77-FD94-0005-1633-C23F94FDD101}" />
  8352. <Execution ProcessID="968" ThreadID="4980" />
  8353. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8354. <Computer>DESKTOP-D07KK79</Computer>
  8355. <Security UserID="S-1-5-18" />
  8356. </System>
  8357. <EventData>
  8358. <Data Name="ErrorCode">1168</Data>
  8359. <Data Name="PackageFullName">Microsoft.Getstarted_3.11.3.0_x64__8wekyb3d8bbwe</Data>
  8360. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8361. <Data Name="DesiredStatus">32</Data>
  8362. <Data Name="CurrentStatus">0</Data>
  8363. </EventData>
  8364. </Event>
  8365.  
  8366. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8367. Source: Microsoft-Windows-AppModel-Runtime
  8368. Date: 8/23/2016 4:19:56 PM
  8369. Event ID: 69
  8370. Task Category: None
  8371. Level: Error
  8372. Keywords: (70368744177664),Process
  8373. User: SYSTEM
  8374. Computer: DESKTOP-D07KK79
  8375. Description:
  8376. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.BingWeather_4.9.51.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8377. Event Xml:
  8378. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8379. <System>
  8380. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8381. <EventID>69</EventID>
  8382. <Version>0</Version>
  8383. <Level>2</Level>
  8384. <Task>0</Task>
  8385. <Opcode>0</Opcode>
  8386. <Keywords>0x2000400000000001</Keywords>
  8387. <TimeCreated SystemTime="2016-08-23T23:19:56.622740700Z" />
  8388. <EventRecordID>59</EventRecordID>
  8389. <Correlation ActivityID="{3FC22F77-FD94-0001-2831-C23F94FDD101}" />
  8390. <Execution ProcessID="968" ThreadID="4980" />
  8391. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8392. <Computer>DESKTOP-D07KK79</Computer>
  8393. <Security UserID="S-1-5-18" />
  8394. </System>
  8395. <EventData>
  8396. <Data Name="ErrorCode">1168</Data>
  8397. <Data Name="PackageFullName">Microsoft.BingWeather_4.9.51.0_x86__8wekyb3d8bbwe</Data>
  8398. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8399. <Data Name="DesiredStatus">32</Data>
  8400. <Data Name="CurrentStatus">0</Data>
  8401. </EventData>
  8402. </Event>
  8403.  
  8404. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8405. Source: Microsoft-Windows-AppModel-Runtime
  8406. Date: 8/23/2016 4:19:56 PM
  8407. Event ID: 69
  8408. Task Category: None
  8409. Level: Error
  8410. Keywords: (70368744177664),Process
  8411. User: SYSTEM
  8412. Computer: DESKTOP-D07KK79
  8413. Description:
  8414. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Framework.1.3_1.3.23901.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8415. Event Xml:
  8416. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8417. <System>
  8418. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8419. <EventID>69</EventID>
  8420. <Version>0</Version>
  8421. <Level>2</Level>
  8422. <Task>0</Task>
  8423. <Opcode>0</Opcode>
  8424. <Keywords>0x2000400000000001</Keywords>
  8425. <TimeCreated SystemTime="2016-08-23T23:19:56.622692300Z" />
  8426. <EventRecordID>58</EventRecordID>
  8427. <Correlation ActivityID="{3FC22F77-FD94-0001-2831-C23F94FDD101}" />
  8428. <Execution ProcessID="968" ThreadID="4980" />
  8429. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8430. <Computer>DESKTOP-D07KK79</Computer>
  8431. <Security UserID="S-1-5-18" />
  8432. </System>
  8433. <EventData>
  8434. <Data Name="ErrorCode">1168</Data>
  8435. <Data Name="PackageFullName">Microsoft.NET.Native.Framework.1.3_1.3.23901.0_x86__8wekyb3d8bbwe</Data>
  8436. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8437. <Data Name="DesiredStatus">32</Data>
  8438. <Data Name="CurrentStatus">0</Data>
  8439. </EventData>
  8440. </Event>
  8441.  
  8442. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8443. Source: Microsoft-Windows-AppModel-Runtime
  8444. Date: 8/23/2016 4:19:56 PM
  8445. Event ID: 69
  8446. Task Category: None
  8447. Level: Error
  8448. Keywords: (70368744177664),Process
  8449. User: SYSTEM
  8450. Computer: DESKTOP-D07KK79
  8451. Description:
  8452. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Framework.1.3_1.3.23901.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8453. Event Xml:
  8454. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8455. <System>
  8456. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8457. <EventID>69</EventID>
  8458. <Version>0</Version>
  8459. <Level>2</Level>
  8460. <Task>0</Task>
  8461. <Opcode>0</Opcode>
  8462. <Keywords>0x2000400000000001</Keywords>
  8463. <TimeCreated SystemTime="2016-08-23T23:19:56.622645100Z" />
  8464. <EventRecordID>57</EventRecordID>
  8465. <Correlation ActivityID="{3FC22F77-FD94-0001-2831-C23F94FDD101}" />
  8466. <Execution ProcessID="968" ThreadID="4980" />
  8467. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8468. <Computer>DESKTOP-D07KK79</Computer>
  8469. <Security UserID="S-1-5-18" />
  8470. </System>
  8471. <EventData>
  8472. <Data Name="ErrorCode">1168</Data>
  8473. <Data Name="PackageFullName">Microsoft.NET.Native.Framework.1.3_1.3.23901.0_x64__8wekyb3d8bbwe</Data>
  8474. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8475. <Data Name="DesiredStatus">32</Data>
  8476. <Data Name="CurrentStatus">0</Data>
  8477. </EventData>
  8478. </Event>
  8479.  
  8480. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8481. Source: Microsoft-Windows-AppModel-Runtime
  8482. Date: 8/23/2016 4:19:56 PM
  8483. Event ID: 69
  8484. Task Category: None
  8485. Level: Error
  8486. Keywords: (70368744177664),Process
  8487. User: SYSTEM
  8488. Computer: DESKTOP-D07KK79
  8489. Description:
  8490. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8491. Event Xml:
  8492. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8493. <System>
  8494. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8495. <EventID>69</EventID>
  8496. <Version>0</Version>
  8497. <Level>2</Level>
  8498. <Task>0</Task>
  8499. <Opcode>0</Opcode>
  8500. <Keywords>0x2000400000000001</Keywords>
  8501. <TimeCreated SystemTime="2016-08-23T23:19:56.622593400Z" />
  8502. <EventRecordID>56</EventRecordID>
  8503. <Correlation ActivityID="{3FC22F77-FD94-0001-2831-C23F94FDD101}" />
  8504. <Execution ProcessID="968" ThreadID="4980" />
  8505. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8506. <Computer>DESKTOP-D07KK79</Computer>
  8507. <Security UserID="S-1-5-18" />
  8508. </System>
  8509. <EventData>
  8510. <Data Name="ErrorCode">1168</Data>
  8511. <Data Name="PackageFullName">Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x86__8wekyb3d8bbwe</Data>
  8512. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8513. <Data Name="DesiredStatus">32</Data>
  8514. <Data Name="CurrentStatus">0</Data>
  8515. </EventData>
  8516. </Event>
  8517.  
  8518. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8519. Source: Microsoft-Windows-AppModel-Runtime
  8520. Date: 8/23/2016 4:19:56 PM
  8521. Event ID: 69
  8522. Task Category: None
  8523. Level: Error
  8524. Keywords: (70368744177664),Process
  8525. User: SYSTEM
  8526. Computer: DESKTOP-D07KK79
  8527. Description:
  8528. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8529. Event Xml:
  8530. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8531. <System>
  8532. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8533. <EventID>69</EventID>
  8534. <Version>0</Version>
  8535. <Level>2</Level>
  8536. <Task>0</Task>
  8537. <Opcode>0</Opcode>
  8538. <Keywords>0x2000400000000001</Keywords>
  8539. <TimeCreated SystemTime="2016-08-23T23:19:56.622532400Z" />
  8540. <EventRecordID>55</EventRecordID>
  8541. <Correlation ActivityID="{3FC22F77-FD94-0001-2831-C23F94FDD101}" />
  8542. <Execution ProcessID="968" ThreadID="4980" />
  8543. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8544. <Computer>DESKTOP-D07KK79</Computer>
  8545. <Security UserID="S-1-5-18" />
  8546. </System>
  8547. <EventData>
  8548. <Data Name="ErrorCode">1168</Data>
  8549. <Data Name="PackageFullName">Microsoft.NET.Native.Runtime.1.3_1.3.23901.0_x64__8wekyb3d8bbwe</Data>
  8550. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8551. <Data Name="DesiredStatus">32</Data>
  8552. <Data Name="CurrentStatus">0</Data>
  8553. </EventData>
  8554. </Event>
  8555.  
  8556. Log Name: System
  8557. Source: Microsoft-Windows-DistributedCOM
  8558. Date: 8/23/2016 4:19:56 PM
  8559. Event ID: 10016
  8560. Task Category: None
  8561. Level: Error
  8562. Keywords: Classic
  8563. User: DESKTOP-D07KK79\Enzo
  8564. Computer: DESKTOP-D07KK79
  8565. Description:
  8566. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  8567. {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}
  8568. and APPID
  8569. {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}
  8570. to the user DESKTOP-D07KK79\Enzo SID (S-1-5-21-1999763852-2568256858-2669145966-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708). This security permission can be modified using the Component Services administrative tool.
  8571. Event Xml:
  8572. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8573. <System>
  8574. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  8575. <EventID Qualifiers="0">10016</EventID>
  8576. <Version>0</Version>
  8577. <Level>2</Level>
  8578. <Task>0</Task>
  8579. <Opcode>0</Opcode>
  8580. <Keywords>0x8080000000000000</Keywords>
  8581. <TimeCreated SystemTime="2016-08-23T23:19:56.243327500Z" />
  8582. <EventRecordID>270</EventRecordID>
  8583. <Correlation />
  8584. <Execution ProcessID="860" ThreadID="892" />
  8585. <Channel>System</Channel>
  8586. <Computer>DESKTOP-D07KK79</Computer>
  8587. <Security UserID="S-1-5-21-1999763852-2568256858-2669145966-1001" />
  8588. </System>
  8589. <EventData>
  8590. <Data Name="param1">application-specific</Data>
  8591. <Data Name="param2">Local</Data>
  8592. <Data Name="param3">Activation</Data>
  8593. <Data Name="param4">{260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}</Data>
  8594. <Data Name="param5">{260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}</Data>
  8595. <Data Name="param6">DESKTOP-D07KK79</Data>
  8596. <Data Name="param7">Enzo</Data>
  8597. <Data Name="param8">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8598. <Data Name="param9">LocalHost (Using LRPC)</Data>
  8599. <Data Name="param10">Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  8600. <Data Name="param11">S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708</Data>
  8601. </EventData>
  8602. </Event>
  8603.  
  8604. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8605. Source: Microsoft-Windows-AppModel-Runtime
  8606. Date: 8/23/2016 4:19:55 PM
  8607. Event ID: 69
  8608. Task Category: None
  8609. Level: Error
  8610. Keywords: (70368744177664),Process
  8611. User: SYSTEM
  8612. Computer: DESKTOP-D07KK79
  8613. Description:
  8614. Failed with 0x490 modifying AppModel Runtime status for package microsoft.windowscommunicationsapps_17.6868.41201.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8615. Event Xml:
  8616. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8617. <System>
  8618. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8619. <EventID>69</EventID>
  8620. <Version>0</Version>
  8621. <Level>2</Level>
  8622. <Task>0</Task>
  8623. <Opcode>0</Opcode>
  8624. <Keywords>0x2000400000000001</Keywords>
  8625. <TimeCreated SystemTime="2016-08-23T23:19:55.117318000Z" />
  8626. <EventRecordID>53</EventRecordID>
  8627. <Correlation ActivityID="{3FC22F77-FD94-0000-2F34-C23F94FDD101}" />
  8628. <Execution ProcessID="968" ThreadID="4984" />
  8629. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8630. <Computer>DESKTOP-D07KK79</Computer>
  8631. <Security UserID="S-1-5-18" />
  8632. </System>
  8633. <EventData>
  8634. <Data Name="ErrorCode">1168</Data>
  8635. <Data Name="PackageFullName">microsoft.windowscommunicationsapps_17.6868.41201.0_x64__8wekyb3d8bbwe</Data>
  8636. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8637. <Data Name="DesiredStatus">32</Data>
  8638. <Data Name="CurrentStatus">0</Data>
  8639. </EventData>
  8640. </Event>
  8641.  
  8642. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8643. Source: Microsoft-Windows-AppModel-Runtime
  8644. Date: 8/23/2016 4:19:50 PM
  8645. Event ID: 69
  8646. Task Category: None
  8647. Level: Error
  8648. Keywords: (70368744177664),Process
  8649. User: SYSTEM
  8650. Computer: DESKTOP-D07KK79
  8651. Description:
  8652. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.DesktopAppInstaller_1.0.1471.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8653. Event Xml:
  8654. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8655. <System>
  8656. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8657. <EventID>69</EventID>
  8658. <Version>0</Version>
  8659. <Level>2</Level>
  8660. <Task>0</Task>
  8661. <Opcode>0</Opcode>
  8662. <Keywords>0x2000400000000001</Keywords>
  8663. <TimeCreated SystemTime="2016-08-23T23:19:50.488671100Z" />
  8664. <EventRecordID>49</EventRecordID>
  8665. <Correlation ActivityID="{3FC22F77-FD94-0007-8F31-C23F94FDD101}" />
  8666. <Execution ProcessID="968" ThreadID="4984" />
  8667. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8668. <Computer>DESKTOP-D07KK79</Computer>
  8669. <Security UserID="S-1-5-18" />
  8670. </System>
  8671. <EventData>
  8672. <Data Name="ErrorCode">1168</Data>
  8673. <Data Name="PackageFullName">Microsoft.DesktopAppInstaller_1.0.1471.0_x64__8wekyb3d8bbwe</Data>
  8674. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8675. <Data Name="DesiredStatus">32</Data>
  8676. <Data Name="CurrentStatus">0</Data>
  8677. </EventData>
  8678. </Event>
  8679.  
  8680. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8681. Source: Microsoft-Windows-AppModel-Runtime
  8682. Date: 8/23/2016 4:19:50 PM
  8683. Event ID: 69
  8684. Task Category: None
  8685. Level: Error
  8686. Keywords: (70368744177664),Process
  8687. User: SYSTEM
  8688. Computer: DESKTOP-D07KK79
  8689. Description:
  8690. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.VCLibs.140.00_14.0.23816.0_x64__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8691. Event Xml:
  8692. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8693. <System>
  8694. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8695. <EventID>69</EventID>
  8696. <Version>0</Version>
  8697. <Level>2</Level>
  8698. <Task>0</Task>
  8699. <Opcode>0</Opcode>
  8700. <Keywords>0x2000400000000001</Keywords>
  8701. <TimeCreated SystemTime="2016-08-23T23:19:50.488624900Z" />
  8702. <EventRecordID>48</EventRecordID>
  8703. <Correlation ActivityID="{3FC22F77-FD94-0007-8F31-C23F94FDD101}" />
  8704. <Execution ProcessID="968" ThreadID="4984" />
  8705. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8706. <Computer>DESKTOP-D07KK79</Computer>
  8707. <Security UserID="S-1-5-18" />
  8708. </System>
  8709. <EventData>
  8710. <Data Name="ErrorCode">1168</Data>
  8711. <Data Name="PackageFullName">Microsoft.VCLibs.140.00_14.0.23816.0_x64__8wekyb3d8bbwe</Data>
  8712. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8713. <Data Name="DesiredStatus">32</Data>
  8714. <Data Name="CurrentStatus">0</Data>
  8715. </EventData>
  8716. </Event>
  8717.  
  8718. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8719. Source: Microsoft-Windows-AppModel-Runtime
  8720. Date: 8/23/2016 4:19:50 PM
  8721. Event ID: 69
  8722. Task Category: None
  8723. Level: Error
  8724. Keywords: (70368744177664),Process
  8725. User: SYSTEM
  8726. Computer: DESKTOP-D07KK79
  8727. Description:
  8728. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.VCLibs.140.00_14.0.23816.0_x86__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8729. Event Xml:
  8730. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8731. <System>
  8732. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8733. <EventID>69</EventID>
  8734. <Version>0</Version>
  8735. <Level>2</Level>
  8736. <Task>0</Task>
  8737. <Opcode>0</Opcode>
  8738. <Keywords>0x2000400000000001</Keywords>
  8739. <TimeCreated SystemTime="2016-08-23T23:19:50.488569500Z" />
  8740. <EventRecordID>47</EventRecordID>
  8741. <Correlation ActivityID="{3FC22F77-FD94-0007-8F31-C23F94FDD101}" />
  8742. <Execution ProcessID="968" ThreadID="4984" />
  8743. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8744. <Computer>DESKTOP-D07KK79</Computer>
  8745. <Security UserID="S-1-5-18" />
  8746. </System>
  8747. <EventData>
  8748. <Data Name="ErrorCode">1168</Data>
  8749. <Data Name="PackageFullName">Microsoft.VCLibs.140.00_14.0.23816.0_x86__8wekyb3d8bbwe</Data>
  8750. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8751. <Data Name="DesiredStatus">32</Data>
  8752. <Data Name="CurrentStatus">0</Data>
  8753. </EventData>
  8754. </Event>
  8755.  
  8756. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8757. Source: Microsoft-Windows-AppModel-Runtime
  8758. Date: 8/23/2016 4:19:48 PM
  8759. Event ID: 69
  8760. Task Category: None
  8761. Level: Error
  8762. Keywords: (70368744177664),Process
  8763. User: SYSTEM
  8764. Computer: DESKTOP-D07KK79
  8765. Description:
  8766. Failed with 0x490 modifying AppModel Runtime status for package Windows.PrintDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8767. Event Xml:
  8768. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8769. <System>
  8770. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8771. <EventID>69</EventID>
  8772. <Version>0</Version>
  8773. <Level>2</Level>
  8774. <Task>0</Task>
  8775. <Opcode>0</Opcode>
  8776. <Keywords>0x2000400000000001</Keywords>
  8777. <TimeCreated SystemTime="2016-08-23T23:19:48.351933900Z" />
  8778. <EventRecordID>46</EventRecordID>
  8779. <Correlation ActivityID="{3FC22F77-FD94-0001-1531-C23F94FDD101}" />
  8780. <Execution ProcessID="968" ThreadID="4980" />
  8781. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8782. <Computer>DESKTOP-D07KK79</Computer>
  8783. <Security UserID="S-1-5-18" />
  8784. </System>
  8785. <EventData>
  8786. <Data Name="ErrorCode">1168</Data>
  8787. <Data Name="PackageFullName">Windows.PrintDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  8788. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8789. <Data Name="DesiredStatus">32</Data>
  8790. <Data Name="CurrentStatus">0</Data>
  8791. </EventData>
  8792. </Event>
  8793.  
  8794. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8795. Source: Microsoft-Windows-AppModel-Runtime
  8796. Date: 8/23/2016 4:19:47 PM
  8797. Event ID: 69
  8798. Task Category: None
  8799. Level: Error
  8800. Keywords: (70368744177664),Process
  8801. User: SYSTEM
  8802. Computer: DESKTOP-D07KK79
  8803. Description:
  8804. Failed with 0x490 modifying AppModel Runtime status for package Windows.MiracastView_6.3.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8805. Event Xml:
  8806. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8807. <System>
  8808. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8809. <EventID>69</EventID>
  8810. <Version>0</Version>
  8811. <Level>2</Level>
  8812. <Task>0</Task>
  8813. <Opcode>0</Opcode>
  8814. <Keywords>0x2000400000000001</Keywords>
  8815. <TimeCreated SystemTime="2016-08-23T23:19:47.932441100Z" />
  8816. <EventRecordID>45</EventRecordID>
  8817. <Correlation ActivityID="{3FC22F77-FD94-0002-0A32-C23F94FDD101}" />
  8818. <Execution ProcessID="968" ThreadID="4980" />
  8819. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8820. <Computer>DESKTOP-D07KK79</Computer>
  8821. <Security UserID="S-1-5-18" />
  8822. </System>
  8823. <EventData>
  8824. <Data Name="ErrorCode">1168</Data>
  8825. <Data Name="PackageFullName">Windows.MiracastView_6.3.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  8826. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8827. <Data Name="DesiredStatus">32</Data>
  8828. <Data Name="CurrentStatus">0</Data>
  8829. </EventData>
  8830. </Event>
  8831.  
  8832. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8833. Source: Microsoft-Windows-AppModel-Runtime
  8834. Date: 8/23/2016 4:19:47 PM
  8835. Event ID: 69
  8836. Task Category: None
  8837. Level: Error
  8838. Keywords: (70368744177664),Process
  8839. User: SYSTEM
  8840. Computer: DESKTOP-D07KK79
  8841. Description:
  8842. Failed with 0x490 modifying AppModel Runtime status for package Windows.ContactSupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8843. Event Xml:
  8844. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8845. <System>
  8846. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8847. <EventID>69</EventID>
  8848. <Version>0</Version>
  8849. <Level>2</Level>
  8850. <Task>0</Task>
  8851. <Opcode>0</Opcode>
  8852. <Keywords>0x2000400000000001</Keywords>
  8853. <TimeCreated SystemTime="2016-08-23T23:19:47.219253100Z" />
  8854. <EventRecordID>43</EventRecordID>
  8855. <Correlation ActivityID="{3FC22F77-FD94-0001-0031-C23F94FDD101}" />
  8856. <Execution ProcessID="968" ThreadID="4980" />
  8857. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8858. <Computer>DESKTOP-D07KK79</Computer>
  8859. <Security UserID="S-1-5-18" />
  8860. </System>
  8861. <EventData>
  8862. <Data Name="ErrorCode">1168</Data>
  8863. <Data Name="PackageFullName">Windows.ContactSupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  8864. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8865. <Data Name="DesiredStatus">32</Data>
  8866. <Data Name="CurrentStatus">0</Data>
  8867. </EventData>
  8868. </Event>
  8869.  
  8870. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8871. Source: Microsoft-Windows-AppModel-Runtime
  8872. Date: 8/23/2016 4:19:46 PM
  8873. Event ID: 69
  8874. Task Category: None
  8875. Level: Error
  8876. Keywords: (70368744177664),Process
  8877. User: SYSTEM
  8878. Computer: DESKTOP-D07KK79
  8879. Description:
  8880. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.XboxGameCallableUI_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8881. Event Xml:
  8882. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8883. <System>
  8884. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8885. <EventID>69</EventID>
  8886. <Version>0</Version>
  8887. <Level>2</Level>
  8888. <Task>0</Task>
  8889. <Opcode>0</Opcode>
  8890. <Keywords>0x2000400000000001</Keywords>
  8891. <TimeCreated SystemTime="2016-08-23T23:19:46.732646700Z" />
  8892. <EventRecordID>41</EventRecordID>
  8893. <Correlation ActivityID="{3FC22F77-FD94-0001-FE30-C23F94FDD101}" />
  8894. <Execution ProcessID="968" ThreadID="4980" />
  8895. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8896. <Computer>DESKTOP-D07KK79</Computer>
  8897. <Security UserID="S-1-5-18" />
  8898. </System>
  8899. <EventData>
  8900. <Data Name="ErrorCode">1168</Data>
  8901. <Data Name="PackageFullName">Microsoft.XboxGameCallableUI_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  8902. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8903. <Data Name="DesiredStatus">32</Data>
  8904. <Data Name="CurrentStatus">0</Data>
  8905. </EventData>
  8906. </Event>
  8907.  
  8908. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8909. Source: Microsoft-Windows-AppModel-Runtime
  8910. Date: 8/23/2016 4:19:45 PM
  8911. Event ID: 69
  8912. Task Category: None
  8913. Level: Error
  8914. Keywords: (70368744177664),Process
  8915. User: SYSTEM
  8916. Computer: DESKTOP-D07KK79
  8917. Description:
  8918. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.SecureAssessmentBrowser_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8919. Event Xml:
  8920. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8921. <System>
  8922. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8923. <EventID>69</EventID>
  8924. <Version>0</Version>
  8925. <Level>2</Level>
  8926. <Task>0</Task>
  8927. <Opcode>0</Opcode>
  8928. <Keywords>0x2000400000000001</Keywords>
  8929. <TimeCreated SystemTime="2016-08-23T23:19:45.654618600Z" />
  8930. <EventRecordID>39</EventRecordID>
  8931. <Correlation ActivityID="{3FC22F77-FD94-0001-E630-C23F94FDD101}" />
  8932. <Execution ProcessID="968" ThreadID="4980" />
  8933. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8934. <Computer>DESKTOP-D07KK79</Computer>
  8935. <Security UserID="S-1-5-18" />
  8936. </System>
  8937. <EventData>
  8938. <Data Name="ErrorCode">1168</Data>
  8939. <Data Name="PackageFullName">Microsoft.Windows.SecureAssessmentBrowser_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  8940. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8941. <Data Name="DesiredStatus">32</Data>
  8942. <Data Name="CurrentStatus">0</Data>
  8943. </EventData>
  8944. </Event>
  8945.  
  8946. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8947. Source: Microsoft-Windows-AppModel-Runtime
  8948. Date: 8/23/2016 4:19:44 PM
  8949. Event ID: 69
  8950. Task Category: None
  8951. Level: Error
  8952. Keywords: (70368744177664),Process
  8953. User: SYSTEM
  8954. Computer: DESKTOP-D07KK79
  8955. Description:
  8956. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.SecondaryTileExperience_10.0.0.0_neutral__cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8957. Event Xml:
  8958. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8959. <System>
  8960. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8961. <EventID>69</EventID>
  8962. <Version>0</Version>
  8963. <Level>2</Level>
  8964. <Task>0</Task>
  8965. <Opcode>0</Opcode>
  8966. <Keywords>0x2000400000000001</Keywords>
  8967. <TimeCreated SystemTime="2016-08-23T23:19:44.828080400Z" />
  8968. <EventRecordID>37</EventRecordID>
  8969. <Correlation ActivityID="{3FC22F77-FD94-0002-F731-C23F94FDD101}" />
  8970. <Execution ProcessID="968" ThreadID="4992" />
  8971. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  8972. <Computer>DESKTOP-D07KK79</Computer>
  8973. <Security UserID="S-1-5-18" />
  8974. </System>
  8975. <EventData>
  8976. <Data Name="ErrorCode">1168</Data>
  8977. <Data Name="PackageFullName">Microsoft.Windows.SecondaryTileExperience_10.0.0.0_neutral__cw5n1h2txyewy</Data>
  8978. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  8979. <Data Name="DesiredStatus">32</Data>
  8980. <Data Name="CurrentStatus">0</Data>
  8981. </EventData>
  8982. </Event>
  8983.  
  8984. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  8985. Source: Microsoft-Windows-AppModel-Runtime
  8986. Date: 8/23/2016 4:19:43 PM
  8987. Event ID: 69
  8988. Task Category: None
  8989. Level: Error
  8990. Keywords: (70368744177664),Process
  8991. User: SYSTEM
  8992. Computer: DESKTOP-D07KK79
  8993. Description:
  8994. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.ParentalControls_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  8995. Event Xml:
  8996. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  8997. <System>
  8998. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  8999. <EventID>69</EventID>
  9000. <Version>0</Version>
  9001. <Level>2</Level>
  9002. <Task>0</Task>
  9003. <Opcode>0</Opcode>
  9004. <Keywords>0x2000400000000001</Keywords>
  9005. <TimeCreated SystemTime="2016-08-23T23:19:43.466157200Z" />
  9006. <EventRecordID>35</EventRecordID>
  9007. <Correlation ActivityID="{3FC22F77-FD94-0003-8B31-C23F94FDD101}" />
  9008. <Execution ProcessID="968" ThreadID="4980" />
  9009. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9010. <Computer>DESKTOP-D07KK79</Computer>
  9011. <Security UserID="S-1-5-18" />
  9012. </System>
  9013. <EventData>
  9014. <Data Name="ErrorCode">1168</Data>
  9015. <Data Name="PackageFullName">Microsoft.Windows.ParentalControls_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  9016. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9017. <Data Name="DesiredStatus">32</Data>
  9018. <Data Name="CurrentStatus">0</Data>
  9019. </EventData>
  9020. </Event>
  9021.  
  9022. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9023. Source: Microsoft-Windows-AppModel-Runtime
  9024. Date: 8/23/2016 4:19:42 PM
  9025. Event ID: 69
  9026. Task Category: None
  9027. Level: Error
  9028. Keywords: (70368744177664),Process
  9029. User: SYSTEM
  9030. Computer: DESKTOP-D07KK79
  9031. Description:
  9032. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.ContentDeliveryManager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9033. Event Xml:
  9034. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9035. <System>
  9036. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9037. <EventID>69</EventID>
  9038. <Version>0</Version>
  9039. <Level>2</Level>
  9040. <Task>0</Task>
  9041. <Opcode>0</Opcode>
  9042. <Keywords>0x2000400000000001</Keywords>
  9043. <TimeCreated SystemTime="2016-08-23T23:19:42.748284900Z" />
  9044. <EventRecordID>33</EventRecordID>
  9045. <Correlation ActivityID="{3FC22F77-FD94-0006-5833-C23F94FDD101}" />
  9046. <Execution ProcessID="968" ThreadID="4992" />
  9047. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9048. <Computer>DESKTOP-D07KK79</Computer>
  9049. <Security UserID="S-1-5-18" />
  9050. </System>
  9051. <EventData>
  9052. <Data Name="ErrorCode">1168</Data>
  9053. <Data Name="PackageFullName">Microsoft.Windows.ContentDeliveryManager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  9054. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9055. <Data Name="DesiredStatus">32</Data>
  9056. <Data Name="CurrentStatus">0</Data>
  9057. </EventData>
  9058. </Event>
  9059.  
  9060. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9061. Source: Microsoft-Windows-AppModel-Runtime
  9062. Date: 8/23/2016 4:19:42 PM
  9063. Event ID: 69
  9064. Task Category: None
  9065. Level: Error
  9066. Keywords: (70368744177664),Process
  9067. User: SYSTEM
  9068. Computer: DESKTOP-D07KK79
  9069. Description:
  9070. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.AssignedAccessLockApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9071. Event Xml:
  9072. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9073. <System>
  9074. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9075. <EventID>69</EventID>
  9076. <Version>0</Version>
  9077. <Level>2</Level>
  9078. <Task>0</Task>
  9079. <Opcode>0</Opcode>
  9080. <Keywords>0x2000400000000001</Keywords>
  9081. <TimeCreated SystemTime="2016-08-23T23:19:42.583447500Z" />
  9082. <EventRecordID>31</EventRecordID>
  9083. <Correlation ActivityID="{3FC22F77-FD94-0001-DA30-C23F94FDD101}" />
  9084. <Execution ProcessID="968" ThreadID="4980" />
  9085. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9086. <Computer>DESKTOP-D07KK79</Computer>
  9087. <Security UserID="S-1-5-18" />
  9088. </System>
  9089. <EventData>
  9090. <Data Name="ErrorCode">1168</Data>
  9091. <Data Name="PackageFullName">Microsoft.Windows.AssignedAccessLockApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  9092. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9093. <Data Name="DesiredStatus">32</Data>
  9094. <Data Name="CurrentStatus">0</Data>
  9095. </EventData>
  9096. </Event>
  9097.  
  9098. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9099. Source: Microsoft-Windows-AppModel-Runtime
  9100. Date: 8/23/2016 4:19:42 PM
  9101. Event ID: 69
  9102. Task Category: None
  9103. Level: Error
  9104. Keywords: (70368744177664),Process
  9105. User: SYSTEM
  9106. Computer: DESKTOP-D07KK79
  9107. Description:
  9108. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.Apprep.ChxApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9109. Event Xml:
  9110. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9111. <System>
  9112. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9113. <EventID>69</EventID>
  9114. <Version>0</Version>
  9115. <Level>2</Level>
  9116. <Task>0</Task>
  9117. <Opcode>0</Opcode>
  9118. <Keywords>0x2000400000000001</Keywords>
  9119. <TimeCreated SystemTime="2016-08-23T23:19:42.201702000Z" />
  9120. <EventRecordID>29</EventRecordID>
  9121. <Correlation ActivityID="{3FC22F77-FD94-0006-5333-C23F94FDD101}" />
  9122. <Execution ProcessID="968" ThreadID="4992" />
  9123. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9124. <Computer>DESKTOP-D07KK79</Computer>
  9125. <Security UserID="S-1-5-18" />
  9126. </System>
  9127. <EventData>
  9128. <Data Name="ErrorCode">1168</Data>
  9129. <Data Name="PackageFullName">Microsoft.Windows.Apprep.ChxApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  9130. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9131. <Data Name="DesiredStatus">32</Data>
  9132. <Data Name="CurrentStatus">0</Data>
  9133. </EventData>
  9134. </Event>
  9135.  
  9136. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9137. Source: Microsoft-Windows-AppModel-Runtime
  9138. Date: 8/23/2016 4:19:41 PM
  9139. Event ID: 69
  9140. Task Category: None
  9141. Level: Error
  9142. Keywords: (70368744177664),Process
  9143. User: SYSTEM
  9144. Computer: DESKTOP-D07KK79
  9145. Description:
  9146. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.PPIProjection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9147. Event Xml:
  9148. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9149. <System>
  9150. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9151. <EventID>69</EventID>
  9152. <Version>0</Version>
  9153. <Level>2</Level>
  9154. <Task>0</Task>
  9155. <Opcode>0</Opcode>
  9156. <Keywords>0x2000400000000001</Keywords>
  9157. <TimeCreated SystemTime="2016-08-23T23:19:41.741130500Z" />
  9158. <EventRecordID>27</EventRecordID>
  9159. <Correlation ActivityID="{3FC22F77-FD94-0004-BB32-C23F94FDD101}" />
  9160. <Execution ProcessID="968" ThreadID="4980" />
  9161. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9162. <Computer>DESKTOP-D07KK79</Computer>
  9163. <Security UserID="S-1-5-18" />
  9164. </System>
  9165. <EventData>
  9166. <Data Name="ErrorCode">1168</Data>
  9167. <Data Name="PackageFullName">Microsoft.PPIProjection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  9168. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9169. <Data Name="DesiredStatus">32</Data>
  9170. <Data Name="CurrentStatus">0</Data>
  9171. </EventData>
  9172. </Event>
  9173.  
  9174. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9175. Source: Microsoft-Windows-AppModel-Runtime
  9176. Date: 8/23/2016 4:19:41 PM
  9177. Event ID: 69
  9178. Task Category: None
  9179. Level: Error
  9180. Keywords: (70368744177664),Process
  9181. User: SYSTEM
  9182. Computer: DESKTOP-D07KK79
  9183. Description:
  9184. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9185. Event Xml:
  9186. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9187. <System>
  9188. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9189. <EventID>69</EventID>
  9190. <Version>0</Version>
  9191. <Level>2</Level>
  9192. <Task>0</Task>
  9193. <Opcode>0</Opcode>
  9194. <Keywords>0x2000400000000001</Keywords>
  9195. <TimeCreated SystemTime="2016-08-23T23:19:41.166912500Z" />
  9196. <EventRecordID>25</EventRecordID>
  9197. <Correlation ActivityID="{3FC22F77-FD94-0001-C530-C23F94FDD101}" />
  9198. <Execution ProcessID="968" ThreadID="4992" />
  9199. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9200. <Computer>DESKTOP-D07KK79</Computer>
  9201. <Security UserID="S-1-5-18" />
  9202. </System>
  9203. <EventData>
  9204. <Data Name="ErrorCode">1168</Data>
  9205. <Data Name="PackageFullName">Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe</Data>
  9206. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9207. <Data Name="DesiredStatus">32</Data>
  9208. <Data Name="CurrentStatus">0</Data>
  9209. </EventData>
  9210. </Event>
  9211.  
  9212. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9213. Source: Microsoft-Windows-AppModel-Runtime
  9214. Date: 8/23/2016 4:19:40 PM
  9215. Event ID: 69
  9216. Task Category: None
  9217. Level: Error
  9218. Keywords: (70368744177664),Process
  9219. User: SYSTEM
  9220. Computer: DESKTOP-D07KK79
  9221. Description:
  9222. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.LockApp_10.0.14393.0_neutral__cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9223. Event Xml:
  9224. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9225. <System>
  9226. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9227. <EventID>69</EventID>
  9228. <Version>0</Version>
  9229. <Level>2</Level>
  9230. <Task>0</Task>
  9231. <Opcode>0</Opcode>
  9232. <Keywords>0x2000400000000001</Keywords>
  9233. <TimeCreated SystemTime="2016-08-23T23:19:40.627487000Z" />
  9234. <EventRecordID>23</EventRecordID>
  9235. <Correlation ActivityID="{3FC22F77-FD94-0004-9A32-C23F94FDD101}" />
  9236. <Execution ProcessID="968" ThreadID="4992" />
  9237. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9238. <Computer>DESKTOP-D07KK79</Computer>
  9239. <Security UserID="S-1-5-18" />
  9240. </System>
  9241. <EventData>
  9242. <Data Name="ErrorCode">1168</Data>
  9243. <Data Name="PackageFullName">Microsoft.LockApp_10.0.14393.0_neutral__cw5n1h2txyewy</Data>
  9244. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9245. <Data Name="DesiredStatus">32</Data>
  9246. <Data Name="CurrentStatus">0</Data>
  9247. </EventData>
  9248. </Event>
  9249.  
  9250. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9251. Source: Microsoft-Windows-AppModel-Runtime
  9252. Date: 8/23/2016 4:19:40 PM
  9253. Event ID: 69
  9254. Task Category: None
  9255. Level: Error
  9256. Keywords: (70368744177664),Process
  9257. User: SYSTEM
  9258. Computer: DESKTOP-D07KK79
  9259. Description:
  9260. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.AccountsControl_10.0.14393.0_neutral__cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9261. Event Xml:
  9262. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9263. <System>
  9264. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9265. <EventID>69</EventID>
  9266. <Version>0</Version>
  9267. <Level>2</Level>
  9268. <Task>0</Task>
  9269. <Opcode>0</Opcode>
  9270. <Keywords>0x2000400000000001</Keywords>
  9271. <TimeCreated SystemTime="2016-08-23T23:19:40.124714300Z" />
  9272. <EventRecordID>21</EventRecordID>
  9273. <Correlation ActivityID="{3FC22F77-FD94-0007-2B31-C23F94FDD101}" />
  9274. <Execution ProcessID="968" ThreadID="4992" />
  9275. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9276. <Computer>DESKTOP-D07KK79</Computer>
  9277. <Security UserID="S-1-5-18" />
  9278. </System>
  9279. <EventData>
  9280. <Data Name="ErrorCode">1168</Data>
  9281. <Data Name="PackageFullName">Microsoft.AccountsControl_10.0.14393.0_neutral__cw5n1h2txyewy</Data>
  9282. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9283. <Data Name="DesiredStatus">32</Data>
  9284. <Data Name="CurrentStatus">0</Data>
  9285. </EventData>
  9286. </Event>
  9287.  
  9288. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9289. Source: Microsoft-Windows-AppModel-Runtime
  9290. Date: 8/23/2016 4:19:39 PM
  9291. Event ID: 69
  9292. Task Category: None
  9293. Level: Error
  9294. Keywords: (70368744177664),Process
  9295. User: SYSTEM
  9296. Computer: DESKTOP-D07KK79
  9297. Description:
  9298. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9299. Event Xml:
  9300. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9301. <System>
  9302. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9303. <EventID>69</EventID>
  9304. <Version>0</Version>
  9305. <Level>2</Level>
  9306. <Task>0</Task>
  9307. <Opcode>0</Opcode>
  9308. <Keywords>0x2000400000000001</Keywords>
  9309. <TimeCreated SystemTime="2016-08-23T23:19:39.088551300Z" />
  9310. <EventRecordID>19</EventRecordID>
  9311. <Correlation ActivityID="{3FC22F77-FD94-0001-B730-C23F94FDD101}" />
  9312. <Execution ProcessID="968" ThreadID="4992" />
  9313. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9314. <Computer>DESKTOP-D07KK79</Computer>
  9315. <Security UserID="S-1-5-18" />
  9316. </System>
  9317. <EventData>
  9318. <Data Name="ErrorCode">1168</Data>
  9319. <Data Name="PackageFullName">Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy</Data>
  9320. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9321. <Data Name="DesiredStatus">32</Data>
  9322. <Data Name="CurrentStatus">0</Data>
  9323. </EventData>
  9324. </Event>
  9325.  
  9326. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9327. Source: Microsoft-Windows-AppModel-Runtime
  9328. Date: 8/23/2016 4:19:38 PM
  9329. Event ID: 69
  9330. Task Category: None
  9331. Level: Error
  9332. Keywords: (70368744177664),Process
  9333. User: SYSTEM
  9334. Computer: DESKTOP-D07KK79
  9335. Description:
  9336. Failed with 0x490 modifying AppModel Runtime status for package windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9337. Event Xml:
  9338. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9339. <System>
  9340. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9341. <EventID>69</EventID>
  9342. <Version>0</Version>
  9343. <Level>2</Level>
  9344. <Task>0</Task>
  9345. <Opcode>0</Opcode>
  9346. <Keywords>0x2000400000000001</Keywords>
  9347. <TimeCreated SystemTime="2016-08-23T23:19:38.356326500Z" />
  9348. <EventRecordID>18</EventRecordID>
  9349. <Correlation ActivityID="{3FC22F77-FD94-0002-9C31-C23F94FDD101}" />
  9350. <Execution ProcessID="968" ThreadID="4992" />
  9351. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9352. <Computer>DESKTOP-D07KK79</Computer>
  9353. <Security UserID="S-1-5-18" />
  9354. </System>
  9355. <EventData>
  9356. <Data Name="ErrorCode">1168</Data>
  9357. <Data Name="PackageFullName">windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  9358. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9359. <Data Name="DesiredStatus">32</Data>
  9360. <Data Name="CurrentStatus">0</Data>
  9361. </EventData>
  9362. </Event>
  9363.  
  9364. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9365. Source: Microsoft-Windows-AppModel-Runtime
  9366. Date: 8/23/2016 4:19:35 PM
  9367. Event ID: 69
  9368. Task Category: None
  9369. Level: Error
  9370. Keywords: (70368744177664),Process
  9371. User: SYSTEM
  9372. Computer: DESKTOP-D07KK79
  9373. Description:
  9374. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9375. Event Xml:
  9376. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9377. <System>
  9378. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9379. <EventID>69</EventID>
  9380. <Version>0</Version>
  9381. <Level>2</Level>
  9382. <Task>0</Task>
  9383. <Opcode>0</Opcode>
  9384. <Keywords>0x2000400000000001</Keywords>
  9385. <TimeCreated SystemTime="2016-08-23T23:19:35.569741900Z" />
  9386. <EventRecordID>16</EventRecordID>
  9387. <Correlation ActivityID="{3FC22F77-FD94-0005-5532-C23F94FDD101}" />
  9388. <Execution ProcessID="968" ThreadID="4992" />
  9389. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9390. <Computer>DESKTOP-D07KK79</Computer>
  9391. <Security UserID="S-1-5-18" />
  9392. </System>
  9393. <EventData>
  9394. <Data Name="ErrorCode">1168</Data>
  9395. <Data Name="PackageFullName">Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  9396. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9397. <Data Name="DesiredStatus">32</Data>
  9398. <Data Name="CurrentStatus">0</Data>
  9399. </EventData>
  9400. </Event>
  9401.  
  9402. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9403. Source: Microsoft-Windows-AppModel-Runtime
  9404. Date: 8/23/2016 4:19:34 PM
  9405. Event ID: 69
  9406. Task Category: None
  9407. Level: Error
  9408. Keywords: (70368744177664),Process
  9409. User: SYSTEM
  9410. Computer: DESKTOP-D07KK79
  9411. Description:
  9412. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.CloudExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9413. Event Xml:
  9414. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9415. <System>
  9416. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9417. <EventID>69</EventID>
  9418. <Version>0</Version>
  9419. <Level>2</Level>
  9420. <Task>0</Task>
  9421. <Opcode>0</Opcode>
  9422. <Keywords>0x2000400000000001</Keywords>
  9423. <TimeCreated SystemTime="2016-08-23T23:19:34.591017300Z" />
  9424. <EventRecordID>14</EventRecordID>
  9425. <Correlation ActivityID="{3FC22F77-FD94-0007-CA30-C23F94FDD101}" />
  9426. <Execution ProcessID="968" ThreadID="4980" />
  9427. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9428. <Computer>DESKTOP-D07KK79</Computer>
  9429. <Security UserID="S-1-5-18" />
  9430. </System>
  9431. <EventData>
  9432. <Data Name="ErrorCode">1168</Data>
  9433. <Data Name="PackageFullName">Microsoft.Windows.CloudExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  9434. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9435. <Data Name="DesiredStatus">32</Data>
  9436. <Data Name="CurrentStatus">0</Data>
  9437. </EventData>
  9438. </Event>
  9439.  
  9440. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9441. Source: Microsoft-Windows-AppModel-Runtime
  9442. Date: 8/23/2016 4:19:33 PM
  9443. Event ID: 69
  9444. Task Category: None
  9445. Level: Error
  9446. Keywords: (70368744177664),Process
  9447. User: SYSTEM
  9448. Computer: DESKTOP-D07KK79
  9449. Description:
  9450. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.AAD.BrokerPlugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9451. Event Xml:
  9452. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9453. <System>
  9454. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9455. <EventID>69</EventID>
  9456. <Version>0</Version>
  9457. <Level>2</Level>
  9458. <Task>0</Task>
  9459. <Opcode>0</Opcode>
  9460. <Keywords>0x2000400000000001</Keywords>
  9461. <TimeCreated SystemTime="2016-08-23T23:19:33.010746800Z" />
  9462. <EventRecordID>11</EventRecordID>
  9463. <Correlation ActivityID="{3FC22F77-FD94-0002-3D31-C23F94FDD101}" />
  9464. <Execution ProcessID="968" ThreadID="4980" />
  9465. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9466. <Computer>DESKTOP-D07KK79</Computer>
  9467. <Security UserID="S-1-5-18" />
  9468. </System>
  9469. <EventData>
  9470. <Data Name="ErrorCode">1168</Data>
  9471. <Data Name="PackageFullName">Microsoft.AAD.BrokerPlugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy</Data>
  9472. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9473. <Data Name="DesiredStatus">32</Data>
  9474. <Data Name="CurrentStatus">0</Data>
  9475. </EventData>
  9476. </Event>
  9477.  
  9478. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9479. Source: Microsoft-Windows-AppModel-Runtime
  9480. Date: 8/23/2016 4:19:31 PM
  9481. Event ID: 69
  9482. Task Category: None
  9483. Level: Error
  9484. Keywords: (70368744177664),Process
  9485. User: SYSTEM
  9486. Computer: DESKTOP-D07KK79
  9487. Description:
  9488. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.BioEnrollment_10.0.14393.0_neutral__cw5n1h2txyewy for user DESKTOP-D07KK79\Enzo (current status = 0x0, desired status = 0x20).
  9489. Event Xml:
  9490. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9491. <System>
  9492. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9493. <EventID>69</EventID>
  9494. <Version>0</Version>
  9495. <Level>2</Level>
  9496. <Task>0</Task>
  9497. <Opcode>0</Opcode>
  9498. <Keywords>0x2000400000000001</Keywords>
  9499. <TimeCreated SystemTime="2016-08-23T23:19:31.782931900Z" />
  9500. <EventRecordID>9</EventRecordID>
  9501. <Correlation ActivityID="{3FC22F77-FD94-0002-3C31-C23F94FDD101}" />
  9502. <Execution ProcessID="968" ThreadID="4980" />
  9503. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9504. <Computer>DESKTOP-D07KK79</Computer>
  9505. <Security UserID="S-1-5-18" />
  9506. </System>
  9507. <EventData>
  9508. <Data Name="ErrorCode">1168</Data>
  9509. <Data Name="PackageFullName">Microsoft.BioEnrollment_10.0.14393.0_neutral__cw5n1h2txyewy</Data>
  9510. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1001</Data>
  9511. <Data Name="DesiredStatus">32</Data>
  9512. <Data Name="CurrentStatus">0</Data>
  9513. </EventData>
  9514. </Event>
  9515.  
  9516. Log Name: Microsoft-Windows-DeviceSetupManager/Admin
  9517. Source: Microsoft-Windows-DeviceSetupManager
  9518. Date: 8/23/2016 4:17:59 PM
  9519. Event ID: 123
  9520. Task Category: None
  9521. Level: Warning
  9522. Keywords:
  9523. User: SYSTEM
  9524. Computer: DESKTOP-D07KK79
  9525. Description:
  9526. The DSM service was delayed by 27 seconds for a driver query/download/install on device 'ROOT\BASICDISPLAY\0000'
  9527. Event Xml:
  9528. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9529. <System>
  9530. <Provider Name="Microsoft-Windows-DeviceSetupManager" Guid="{FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2}" />
  9531. <EventID>123</EventID>
  9532. <Version>0</Version>
  9533. <Level>3</Level>
  9534. <Task>0</Task>
  9535. <Opcode>0</Opcode>
  9536. <Keywords>0x4000000000000000</Keywords>
  9537. <TimeCreated SystemTime="2016-08-23T23:17:59.786202400Z" />
  9538. <EventRecordID>11</EventRecordID>
  9539. <Correlation ActivityID="{3FC22F77-FD94-0006-9530-C23F94FDD101}" />
  9540. <Execution ProcessID="1012" ThreadID="1528" />
  9541. <Channel>Microsoft-Windows-DeviceSetupManager/Admin</Channel>
  9542. <Computer>DESKTOP-D07KK79</Computer>
  9543. <Security UserID="S-1-5-18" />
  9544. </System>
  9545. <EventData>
  9546. <Data Name="Prop_Seconds">27</Data>
  9547. <Data Name="Prop_DeviceId">ROOT\BASICDISPLAY\0000</Data>
  9548. </EventData>
  9549. </Event>
  9550.  
  9551. Log Name: System
  9552. Source: Microsoft-Windows-DistributedCOM
  9553. Date: 8/23/2016 4:17:45 PM
  9554. Event ID: 10016
  9555. Task Category: None
  9556. Level: Error
  9557. Keywords: Classic
  9558. User: LOCAL SERVICE
  9559. Computer: DESKTOP-D07KK79
  9560. Description:
  9561. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9562. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9563. and APPID
  9564. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9565. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9566. Event Xml:
  9567. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9568. <System>
  9569. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9570. <EventID Qualifiers="0">10016</EventID>
  9571. <Version>0</Version>
  9572. <Level>2</Level>
  9573. <Task>0</Task>
  9574. <Opcode>0</Opcode>
  9575. <Keywords>0x8080000000000000</Keywords>
  9576. <TimeCreated SystemTime="2016-08-23T23:17:45.287891200Z" />
  9577. <EventRecordID>257</EventRecordID>
  9578. <Correlation />
  9579. <Execution ProcessID="860" ThreadID="896" />
  9580. <Channel>System</Channel>
  9581. <Computer>DESKTOP-D07KK79</Computer>
  9582. <Security UserID="S-1-5-19" />
  9583. </System>
  9584. <EventData>
  9585. <Data Name="param1">application-specific</Data>
  9586. <Data Name="param2">Local</Data>
  9587. <Data Name="param3">Activation</Data>
  9588. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9589. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9590. <Data Name="param6">NT AUTHORITY</Data>
  9591. <Data Name="param7">LOCAL SERVICE</Data>
  9592. <Data Name="param8">S-1-5-19</Data>
  9593. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9594. <Data Name="param10">Unavailable</Data>
  9595. <Data Name="param11">Unavailable</Data>
  9596. </EventData>
  9597. </Event>
  9598.  
  9599. Log Name: System
  9600. Source: Microsoft-Windows-DistributedCOM
  9601. Date: 8/23/2016 4:17:45 PM
  9602. Event ID: 10016
  9603. Task Category: None
  9604. Level: Error
  9605. Keywords: Classic
  9606. User: LOCAL SERVICE
  9607. Computer: DESKTOP-D07KK79
  9608. Description:
  9609. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9610. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9611. and APPID
  9612. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9613. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9614. Event Xml:
  9615. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9616. <System>
  9617. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9618. <EventID Qualifiers="0">10016</EventID>
  9619. <Version>0</Version>
  9620. <Level>2</Level>
  9621. <Task>0</Task>
  9622. <Opcode>0</Opcode>
  9623. <Keywords>0x8080000000000000</Keywords>
  9624. <TimeCreated SystemTime="2016-08-23T23:17:45.103875200Z" />
  9625. <EventRecordID>256</EventRecordID>
  9626. <Correlation />
  9627. <Execution ProcessID="860" ThreadID="896" />
  9628. <Channel>System</Channel>
  9629. <Computer>DESKTOP-D07KK79</Computer>
  9630. <Security UserID="S-1-5-19" />
  9631. </System>
  9632. <EventData>
  9633. <Data Name="param1">application-specific</Data>
  9634. <Data Name="param2">Local</Data>
  9635. <Data Name="param3">Activation</Data>
  9636. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9637. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9638. <Data Name="param6">NT AUTHORITY</Data>
  9639. <Data Name="param7">LOCAL SERVICE</Data>
  9640. <Data Name="param8">S-1-5-19</Data>
  9641. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9642. <Data Name="param10">Unavailable</Data>
  9643. <Data Name="param11">Unavailable</Data>
  9644. </EventData>
  9645. </Event>
  9646.  
  9647. Log Name: System
  9648. Source: Service Control Manager
  9649. Date: 8/23/2016 4:17:45 PM
  9650. Event ID: 7030
  9651. Task Category: None
  9652. Level: Error
  9653. Keywords: Classic
  9654. User: N/A
  9655. Computer: DESKTOP-D07KK79
  9656. Description:
  9657. The Printer Extensions and Notifications service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
  9658. Event Xml:
  9659. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9660. <System>
  9661. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  9662. <EventID Qualifiers="49152">7030</EventID>
  9663. <Version>0</Version>
  9664. <Level>2</Level>
  9665. <Task>0</Task>
  9666. <Opcode>0</Opcode>
  9667. <Keywords>0x8080000000000000</Keywords>
  9668. <TimeCreated SystemTime="2016-08-23T23:17:45.040869900Z" />
  9669. <EventRecordID>255</EventRecordID>
  9670. <Correlation />
  9671. <Execution ProcessID="688" ThreadID="1620" />
  9672. <Channel>System</Channel>
  9673. <Computer>DESKTOP-D07KK79</Computer>
  9674. <Security />
  9675. </System>
  9676. <EventData>
  9677. <Data Name="param1">Printer Extensions and Notifications</Data>
  9678. </EventData>
  9679. </Event>
  9680.  
  9681. Log Name: System
  9682. Source: Microsoft-Windows-DistributedCOM
  9683. Date: 8/23/2016 4:17:44 PM
  9684. Event ID: 10016
  9685. Task Category: None
  9686. Level: Error
  9687. Keywords: Classic
  9688. User: LOCAL SERVICE
  9689. Computer: DESKTOP-D07KK79
  9690. Description:
  9691. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9692. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9693. and APPID
  9694. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9695. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9696. Event Xml:
  9697. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9698. <System>
  9699. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9700. <EventID Qualifiers="0">10016</EventID>
  9701. <Version>0</Version>
  9702. <Level>2</Level>
  9703. <Task>0</Task>
  9704. <Opcode>0</Opcode>
  9705. <Keywords>0x8080000000000000</Keywords>
  9706. <TimeCreated SystemTime="2016-08-23T23:17:44.928860100Z" />
  9707. <EventRecordID>253</EventRecordID>
  9708. <Correlation />
  9709. <Execution ProcessID="860" ThreadID="896" />
  9710. <Channel>System</Channel>
  9711. <Computer>DESKTOP-D07KK79</Computer>
  9712. <Security UserID="S-1-5-19" />
  9713. </System>
  9714. <EventData>
  9715. <Data Name="param1">application-specific</Data>
  9716. <Data Name="param2">Local</Data>
  9717. <Data Name="param3">Activation</Data>
  9718. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9719. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9720. <Data Name="param6">NT AUTHORITY</Data>
  9721. <Data Name="param7">LOCAL SERVICE</Data>
  9722. <Data Name="param8">S-1-5-19</Data>
  9723. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9724. <Data Name="param10">Unavailable</Data>
  9725. <Data Name="param11">Unavailable</Data>
  9726. </EventData>
  9727. </Event>
  9728.  
  9729. Log Name: System
  9730. Source: Microsoft-Windows-DistributedCOM
  9731. Date: 8/23/2016 4:17:44 PM
  9732. Event ID: 10016
  9733. Task Category: None
  9734. Level: Error
  9735. Keywords: Classic
  9736. User: LOCAL SERVICE
  9737. Computer: DESKTOP-D07KK79
  9738. Description:
  9739. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9740. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9741. and APPID
  9742. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9743. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9744. Event Xml:
  9745. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9746. <System>
  9747. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9748. <EventID Qualifiers="0">10016</EventID>
  9749. <Version>0</Version>
  9750. <Level>2</Level>
  9751. <Task>0</Task>
  9752. <Opcode>0</Opcode>
  9753. <Keywords>0x8080000000000000</Keywords>
  9754. <TimeCreated SystemTime="2016-08-23T23:17:44.743844000Z" />
  9755. <EventRecordID>252</EventRecordID>
  9756. <Correlation />
  9757. <Execution ProcessID="860" ThreadID="592" />
  9758. <Channel>System</Channel>
  9759. <Computer>DESKTOP-D07KK79</Computer>
  9760. <Security UserID="S-1-5-19" />
  9761. </System>
  9762. <EventData>
  9763. <Data Name="param1">application-specific</Data>
  9764. <Data Name="param2">Local</Data>
  9765. <Data Name="param3">Activation</Data>
  9766. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9767. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9768. <Data Name="param6">NT AUTHORITY</Data>
  9769. <Data Name="param7">LOCAL SERVICE</Data>
  9770. <Data Name="param8">S-1-5-19</Data>
  9771. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9772. <Data Name="param10">Unavailable</Data>
  9773. <Data Name="param11">Unavailable</Data>
  9774. </EventData>
  9775. </Event>
  9776.  
  9777. Log Name: System
  9778. Source: Microsoft-Windows-DistributedCOM
  9779. Date: 8/23/2016 4:17:44 PM
  9780. Event ID: 10016
  9781. Task Category: None
  9782. Level: Error
  9783. Keywords: Classic
  9784. User: LOCAL SERVICE
  9785. Computer: DESKTOP-D07KK79
  9786. Description:
  9787. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9788. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9789. and APPID
  9790. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9791. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9792. Event Xml:
  9793. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9794. <System>
  9795. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9796. <EventID Qualifiers="0">10016</EventID>
  9797. <Version>0</Version>
  9798. <Level>2</Level>
  9799. <Task>0</Task>
  9800. <Opcode>0</Opcode>
  9801. <Keywords>0x8080000000000000</Keywords>
  9802. <TimeCreated SystemTime="2016-08-23T23:17:44.532825300Z" />
  9803. <EventRecordID>251</EventRecordID>
  9804. <Correlation />
  9805. <Execution ProcessID="860" ThreadID="896" />
  9806. <Channel>System</Channel>
  9807. <Computer>DESKTOP-D07KK79</Computer>
  9808. <Security UserID="S-1-5-19" />
  9809. </System>
  9810. <EventData>
  9811. <Data Name="param1">application-specific</Data>
  9812. <Data Name="param2">Local</Data>
  9813. <Data Name="param3">Activation</Data>
  9814. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9815. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9816. <Data Name="param6">NT AUTHORITY</Data>
  9817. <Data Name="param7">LOCAL SERVICE</Data>
  9818. <Data Name="param8">S-1-5-19</Data>
  9819. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9820. <Data Name="param10">Unavailable</Data>
  9821. <Data Name="param11">Unavailable</Data>
  9822. </EventData>
  9823. </Event>
  9824.  
  9825. Log Name: System
  9826. Source: Microsoft-Windows-DistributedCOM
  9827. Date: 8/23/2016 4:17:44 PM
  9828. Event ID: 10016
  9829. Task Category: None
  9830. Level: Error
  9831. Keywords: Classic
  9832. User: LOCAL SERVICE
  9833. Computer: DESKTOP-D07KK79
  9834. Description:
  9835. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9836. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9837. and APPID
  9838. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9839. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9840. Event Xml:
  9841. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9842. <System>
  9843. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9844. <EventID Qualifiers="0">10016</EventID>
  9845. <Version>0</Version>
  9846. <Level>2</Level>
  9847. <Task>0</Task>
  9848. <Opcode>0</Opcode>
  9849. <Keywords>0x8080000000000000</Keywords>
  9850. <TimeCreated SystemTime="2016-08-23T23:17:44.312806300Z" />
  9851. <EventRecordID>250</EventRecordID>
  9852. <Correlation />
  9853. <Execution ProcessID="860" ThreadID="896" />
  9854. <Channel>System</Channel>
  9855. <Computer>DESKTOP-D07KK79</Computer>
  9856. <Security UserID="S-1-5-19" />
  9857. </System>
  9858. <EventData>
  9859. <Data Name="param1">application-specific</Data>
  9860. <Data Name="param2">Local</Data>
  9861. <Data Name="param3">Activation</Data>
  9862. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9863. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9864. <Data Name="param6">NT AUTHORITY</Data>
  9865. <Data Name="param7">LOCAL SERVICE</Data>
  9866. <Data Name="param8">S-1-5-19</Data>
  9867. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9868. <Data Name="param10">Unavailable</Data>
  9869. <Data Name="param11">Unavailable</Data>
  9870. </EventData>
  9871. </Event>
  9872.  
  9873. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  9874. Source: Microsoft-Windows-AppModel-Runtime
  9875. Date: 8/23/2016 4:17:44 PM
  9876. Event ID: 69
  9877. Task Category: None
  9878. Level: Error
  9879. Keywords: (70368744177664),Process
  9880. User: SYSTEM
  9881. Computer: DESKTOP-D07KK79
  9882. Description:
  9883. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.BioEnrollment_10.0.14393.0_neutral__cw5n1h2txyewy for user DESKTOP-D07KK79\defaultuser0 (current status = 0x0, desired status = 0x20).
  9884. Event Xml:
  9885. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9886. <System>
  9887. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  9888. <EventID>69</EventID>
  9889. <Version>0</Version>
  9890. <Level>2</Level>
  9891. <Task>0</Task>
  9892. <Opcode>0</Opcode>
  9893. <Keywords>0x2000400000000001</Keywords>
  9894. <TimeCreated SystemTime="2016-08-23T23:17:44.176327100Z" />
  9895. <EventRecordID>7</EventRecordID>
  9896. <Correlation ActivityID="{3FC22F77-FD94-0006-DF30-C23F94FDD101}" />
  9897. <Execution ProcessID="968" ThreadID="4980" />
  9898. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  9899. <Computer>DESKTOP-D07KK79</Computer>
  9900. <Security UserID="S-1-5-18" />
  9901. </System>
  9902. <EventData>
  9903. <Data Name="ErrorCode">1168</Data>
  9904. <Data Name="PackageFullName">Microsoft.BioEnrollment_10.0.14393.0_neutral__cw5n1h2txyewy</Data>
  9905. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1000</Data>
  9906. <Data Name="DesiredStatus">32</Data>
  9907. <Data Name="CurrentStatus">0</Data>
  9908. </EventData>
  9909. </Event>
  9910.  
  9911. Log Name: System
  9912. Source: Microsoft-Windows-DistributedCOM
  9913. Date: 8/23/2016 4:17:44 PM
  9914. Event ID: 10016
  9915. Task Category: None
  9916. Level: Error
  9917. Keywords: Classic
  9918. User: LOCAL SERVICE
  9919. Computer: DESKTOP-D07KK79
  9920. Description:
  9921. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9922. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9923. and APPID
  9924. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9925. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9926. Event Xml:
  9927. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9928. <System>
  9929. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9930. <EventID Qualifiers="0">10016</EventID>
  9931. <Version>0</Version>
  9932. <Level>2</Level>
  9933. <Task>0</Task>
  9934. <Opcode>0</Opcode>
  9935. <Keywords>0x8080000000000000</Keywords>
  9936. <TimeCreated SystemTime="2016-08-23T23:17:44.130790400Z" />
  9937. <EventRecordID>249</EventRecordID>
  9938. <Correlation />
  9939. <Execution ProcessID="860" ThreadID="896" />
  9940. <Channel>System</Channel>
  9941. <Computer>DESKTOP-D07KK79</Computer>
  9942. <Security UserID="S-1-5-19" />
  9943. </System>
  9944. <EventData>
  9945. <Data Name="param1">application-specific</Data>
  9946. <Data Name="param2">Local</Data>
  9947. <Data Name="param3">Activation</Data>
  9948. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9949. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9950. <Data Name="param6">NT AUTHORITY</Data>
  9951. <Data Name="param7">LOCAL SERVICE</Data>
  9952. <Data Name="param8">S-1-5-19</Data>
  9953. <Data Name="param9">LocalHost (Using LRPC)</Data>
  9954. <Data Name="param10">Unavailable</Data>
  9955. <Data Name="param11">Unavailable</Data>
  9956. </EventData>
  9957. </Event>
  9958.  
  9959. Log Name: System
  9960. Source: Microsoft-Windows-DistributedCOM
  9961. Date: 8/23/2016 4:17:43 PM
  9962. Event ID: 10016
  9963. Task Category: None
  9964. Level: Error
  9965. Keywords: Classic
  9966. User: LOCAL SERVICE
  9967. Computer: DESKTOP-D07KK79
  9968. Description:
  9969. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  9970. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  9971. and APPID
  9972. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  9973. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  9974. Event Xml:
  9975. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  9976. <System>
  9977. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  9978. <EventID Qualifiers="0">10016</EventID>
  9979. <Version>0</Version>
  9980. <Level>2</Level>
  9981. <Task>0</Task>
  9982. <Opcode>0</Opcode>
  9983. <Keywords>0x8080000000000000</Keywords>
  9984. <TimeCreated SystemTime="2016-08-23T23:17:43.950774700Z" />
  9985. <EventRecordID>248</EventRecordID>
  9986. <Correlation />
  9987. <Execution ProcessID="860" ThreadID="896" />
  9988. <Channel>System</Channel>
  9989. <Computer>DESKTOP-D07KK79</Computer>
  9990. <Security UserID="S-1-5-19" />
  9991. </System>
  9992. <EventData>
  9993. <Data Name="param1">application-specific</Data>
  9994. <Data Name="param2">Local</Data>
  9995. <Data Name="param3">Activation</Data>
  9996. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  9997. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  9998. <Data Name="param6">NT AUTHORITY</Data>
  9999. <Data Name="param7">LOCAL SERVICE</Data>
  10000. <Data Name="param8">S-1-5-19</Data>
  10001. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10002. <Data Name="param10">Unavailable</Data>
  10003. <Data Name="param11">Unavailable</Data>
  10004. </EventData>
  10005. </Event>
  10006.  
  10007. Log Name: System
  10008. Source: Microsoft-Windows-DistributedCOM
  10009. Date: 8/23/2016 4:17:43 PM
  10010. Event ID: 10016
  10011. Task Category: None
  10012. Level: Error
  10013. Keywords: Classic
  10014. User: LOCAL SERVICE
  10015. Computer: DESKTOP-D07KK79
  10016. Description:
  10017. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10018. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10019. and APPID
  10020. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10021. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10022. Event Xml:
  10023. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10024. <System>
  10025. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10026. <EventID Qualifiers="0">10016</EventID>
  10027. <Version>0</Version>
  10028. <Level>2</Level>
  10029. <Task>0</Task>
  10030. <Opcode>0</Opcode>
  10031. <Keywords>0x8080000000000000</Keywords>
  10032. <TimeCreated SystemTime="2016-08-23T23:17:43.766758600Z" />
  10033. <EventRecordID>247</EventRecordID>
  10034. <Correlation />
  10035. <Execution ProcessID="860" ThreadID="896" />
  10036. <Channel>System</Channel>
  10037. <Computer>DESKTOP-D07KK79</Computer>
  10038. <Security UserID="S-1-5-19" />
  10039. </System>
  10040. <EventData>
  10041. <Data Name="param1">application-specific</Data>
  10042. <Data Name="param2">Local</Data>
  10043. <Data Name="param3">Activation</Data>
  10044. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10045. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10046. <Data Name="param6">NT AUTHORITY</Data>
  10047. <Data Name="param7">LOCAL SERVICE</Data>
  10048. <Data Name="param8">S-1-5-19</Data>
  10049. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10050. <Data Name="param10">Unavailable</Data>
  10051. <Data Name="param11">Unavailable</Data>
  10052. </EventData>
  10053. </Event>
  10054.  
  10055. Log Name: System
  10056. Source: Microsoft-Windows-DistributedCOM
  10057. Date: 8/23/2016 4:17:43 PM
  10058. Event ID: 10016
  10059. Task Category: None
  10060. Level: Error
  10061. Keywords: Classic
  10062. User: LOCAL SERVICE
  10063. Computer: DESKTOP-D07KK79
  10064. Description:
  10065. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10066. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10067. and APPID
  10068. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10069. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10070. Event Xml:
  10071. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10072. <System>
  10073. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10074. <EventID Qualifiers="0">10016</EventID>
  10075. <Version>0</Version>
  10076. <Level>2</Level>
  10077. <Task>0</Task>
  10078. <Opcode>0</Opcode>
  10079. <Keywords>0x8080000000000000</Keywords>
  10080. <TimeCreated SystemTime="2016-08-23T23:17:43.588743100Z" />
  10081. <EventRecordID>246</EventRecordID>
  10082. <Correlation />
  10083. <Execution ProcessID="860" ThreadID="592" />
  10084. <Channel>System</Channel>
  10085. <Computer>DESKTOP-D07KK79</Computer>
  10086. <Security UserID="S-1-5-19" />
  10087. </System>
  10088. <EventData>
  10089. <Data Name="param1">application-specific</Data>
  10090. <Data Name="param2">Local</Data>
  10091. <Data Name="param3">Activation</Data>
  10092. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10093. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10094. <Data Name="param6">NT AUTHORITY</Data>
  10095. <Data Name="param7">LOCAL SERVICE</Data>
  10096. <Data Name="param8">S-1-5-19</Data>
  10097. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10098. <Data Name="param10">Unavailable</Data>
  10099. <Data Name="param11">Unavailable</Data>
  10100. </EventData>
  10101. </Event>
  10102.  
  10103. Log Name: System
  10104. Source: Microsoft-Windows-DistributedCOM
  10105. Date: 8/23/2016 4:17:43 PM
  10106. Event ID: 10016
  10107. Task Category: None
  10108. Level: Error
  10109. Keywords: Classic
  10110. User: LOCAL SERVICE
  10111. Computer: DESKTOP-D07KK79
  10112. Description:
  10113. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10114. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10115. and APPID
  10116. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10117. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10118. Event Xml:
  10119. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10120. <System>
  10121. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10122. <EventID Qualifiers="0">10016</EventID>
  10123. <Version>0</Version>
  10124. <Level>2</Level>
  10125. <Task>0</Task>
  10126. <Opcode>0</Opcode>
  10127. <Keywords>0x8080000000000000</Keywords>
  10128. <TimeCreated SystemTime="2016-08-23T23:17:43.391725900Z" />
  10129. <EventRecordID>245</EventRecordID>
  10130. <Correlation />
  10131. <Execution ProcessID="860" ThreadID="592" />
  10132. <Channel>System</Channel>
  10133. <Computer>DESKTOP-D07KK79</Computer>
  10134. <Security UserID="S-1-5-19" />
  10135. </System>
  10136. <EventData>
  10137. <Data Name="param1">application-specific</Data>
  10138. <Data Name="param2">Local</Data>
  10139. <Data Name="param3">Activation</Data>
  10140. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10141. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10142. <Data Name="param6">NT AUTHORITY</Data>
  10143. <Data Name="param7">LOCAL SERVICE</Data>
  10144. <Data Name="param8">S-1-5-19</Data>
  10145. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10146. <Data Name="param10">Unavailable</Data>
  10147. <Data Name="param11">Unavailable</Data>
  10148. </EventData>
  10149. </Event>
  10150.  
  10151. Log Name: System
  10152. Source: Microsoft-Windows-DistributedCOM
  10153. Date: 8/23/2016 4:17:43 PM
  10154. Event ID: 10016
  10155. Task Category: None
  10156. Level: Error
  10157. Keywords: Classic
  10158. User: LOCAL SERVICE
  10159. Computer: DESKTOP-D07KK79
  10160. Description:
  10161. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10162. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10163. and APPID
  10164. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10165. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10166. Event Xml:
  10167. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10168. <System>
  10169. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10170. <EventID Qualifiers="0">10016</EventID>
  10171. <Version>0</Version>
  10172. <Level>2</Level>
  10173. <Task>0</Task>
  10174. <Opcode>0</Opcode>
  10175. <Keywords>0x8080000000000000</Keywords>
  10176. <TimeCreated SystemTime="2016-08-23T23:17:43.162705900Z" />
  10177. <EventRecordID>244</EventRecordID>
  10178. <Correlation />
  10179. <Execution ProcessID="860" ThreadID="592" />
  10180. <Channel>System</Channel>
  10181. <Computer>DESKTOP-D07KK79</Computer>
  10182. <Security UserID="S-1-5-19" />
  10183. </System>
  10184. <EventData>
  10185. <Data Name="param1">application-specific</Data>
  10186. <Data Name="param2">Local</Data>
  10187. <Data Name="param3">Activation</Data>
  10188. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10189. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10190. <Data Name="param6">NT AUTHORITY</Data>
  10191. <Data Name="param7">LOCAL SERVICE</Data>
  10192. <Data Name="param8">S-1-5-19</Data>
  10193. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10194. <Data Name="param10">Unavailable</Data>
  10195. <Data Name="param11">Unavailable</Data>
  10196. </EventData>
  10197. </Event>
  10198.  
  10199. Log Name: System
  10200. Source: Microsoft-Windows-DistributedCOM
  10201. Date: 8/23/2016 4:17:42 PM
  10202. Event ID: 10016
  10203. Task Category: None
  10204. Level: Error
  10205. Keywords: Classic
  10206. User: LOCAL SERVICE
  10207. Computer: DESKTOP-D07KK79
  10208. Description:
  10209. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10210. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10211. and APPID
  10212. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10213. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10214. Event Xml:
  10215. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10216. <System>
  10217. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10218. <EventID Qualifiers="0">10016</EventID>
  10219. <Version>0</Version>
  10220. <Level>2</Level>
  10221. <Task>0</Task>
  10222. <Opcode>0</Opcode>
  10223. <Keywords>0x8080000000000000</Keywords>
  10224. <TimeCreated SystemTime="2016-08-23T23:17:42.969689300Z" />
  10225. <EventRecordID>243</EventRecordID>
  10226. <Correlation />
  10227. <Execution ProcessID="860" ThreadID="592" />
  10228. <Channel>System</Channel>
  10229. <Computer>DESKTOP-D07KK79</Computer>
  10230. <Security UserID="S-1-5-19" />
  10231. </System>
  10232. <EventData>
  10233. <Data Name="param1">application-specific</Data>
  10234. <Data Name="param2">Local</Data>
  10235. <Data Name="param3">Activation</Data>
  10236. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10237. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10238. <Data Name="param6">NT AUTHORITY</Data>
  10239. <Data Name="param7">LOCAL SERVICE</Data>
  10240. <Data Name="param8">S-1-5-19</Data>
  10241. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10242. <Data Name="param10">Unavailable</Data>
  10243. <Data Name="param11">Unavailable</Data>
  10244. </EventData>
  10245. </Event>
  10246.  
  10247. Log Name: System
  10248. Source: Microsoft-Windows-DistributedCOM
  10249. Date: 8/23/2016 4:17:42 PM
  10250. Event ID: 10016
  10251. Task Category: None
  10252. Level: Error
  10253. Keywords: Classic
  10254. User: LOCAL SERVICE
  10255. Computer: DESKTOP-D07KK79
  10256. Description:
  10257. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10258. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10259. and APPID
  10260. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10261. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10262. Event Xml:
  10263. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10264. <System>
  10265. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10266. <EventID Qualifiers="0">10016</EventID>
  10267. <Version>0</Version>
  10268. <Level>2</Level>
  10269. <Task>0</Task>
  10270. <Opcode>0</Opcode>
  10271. <Keywords>0x8080000000000000</Keywords>
  10272. <TimeCreated SystemTime="2016-08-23T23:17:42.793673900Z" />
  10273. <EventRecordID>242</EventRecordID>
  10274. <Correlation />
  10275. <Execution ProcessID="860" ThreadID="896" />
  10276. <Channel>System</Channel>
  10277. <Computer>DESKTOP-D07KK79</Computer>
  10278. <Security UserID="S-1-5-19" />
  10279. </System>
  10280. <EventData>
  10281. <Data Name="param1">application-specific</Data>
  10282. <Data Name="param2">Local</Data>
  10283. <Data Name="param3">Activation</Data>
  10284. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10285. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10286. <Data Name="param6">NT AUTHORITY</Data>
  10287. <Data Name="param7">LOCAL SERVICE</Data>
  10288. <Data Name="param8">S-1-5-19</Data>
  10289. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10290. <Data Name="param10">Unavailable</Data>
  10291. <Data Name="param11">Unavailable</Data>
  10292. </EventData>
  10293. </Event>
  10294.  
  10295. Log Name: System
  10296. Source: Microsoft-Windows-DistributedCOM
  10297. Date: 8/23/2016 4:17:42 PM
  10298. Event ID: 10016
  10299. Task Category: None
  10300. Level: Error
  10301. Keywords: Classic
  10302. User: LOCAL SERVICE
  10303. Computer: DESKTOP-D07KK79
  10304. Description:
  10305. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10306. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10307. and APPID
  10308. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10309. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10310. Event Xml:
  10311. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10312. <System>
  10313. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10314. <EventID Qualifiers="0">10016</EventID>
  10315. <Version>0</Version>
  10316. <Level>2</Level>
  10317. <Task>0</Task>
  10318. <Opcode>0</Opcode>
  10319. <Keywords>0x8080000000000000</Keywords>
  10320. <TimeCreated SystemTime="2016-08-23T23:17:42.349634900Z" />
  10321. <EventRecordID>241</EventRecordID>
  10322. <Correlation />
  10323. <Execution ProcessID="860" ThreadID="896" />
  10324. <Channel>System</Channel>
  10325. <Computer>DESKTOP-D07KK79</Computer>
  10326. <Security UserID="S-1-5-19" />
  10327. </System>
  10328. <EventData>
  10329. <Data Name="param1">application-specific</Data>
  10330. <Data Name="param2">Local</Data>
  10331. <Data Name="param3">Activation</Data>
  10332. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10333. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10334. <Data Name="param6">NT AUTHORITY</Data>
  10335. <Data Name="param7">LOCAL SERVICE</Data>
  10336. <Data Name="param8">S-1-5-19</Data>
  10337. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10338. <Data Name="param10">Unavailable</Data>
  10339. <Data Name="param11">Unavailable</Data>
  10340. </EventData>
  10341. </Event>
  10342.  
  10343. Log Name: System
  10344. Source: Microsoft-Windows-DistributedCOM
  10345. Date: 8/23/2016 4:17:42 PM
  10346. Event ID: 10016
  10347. Task Category: None
  10348. Level: Error
  10349. Keywords: Classic
  10350. User: LOCAL SERVICE
  10351. Computer: DESKTOP-D07KK79
  10352. Description:
  10353. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10354. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10355. and APPID
  10356. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10357. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10358. Event Xml:
  10359. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10360. <System>
  10361. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10362. <EventID Qualifiers="0">10016</EventID>
  10363. <Version>0</Version>
  10364. <Level>2</Level>
  10365. <Task>0</Task>
  10366. <Opcode>0</Opcode>
  10367. <Keywords>0x8080000000000000</Keywords>
  10368. <TimeCreated SystemTime="2016-08-23T23:17:42.162618800Z" />
  10369. <EventRecordID>240</EventRecordID>
  10370. <Correlation />
  10371. <Execution ProcessID="860" ThreadID="592" />
  10372. <Channel>System</Channel>
  10373. <Computer>DESKTOP-D07KK79</Computer>
  10374. <Security UserID="S-1-5-19" />
  10375. </System>
  10376. <EventData>
  10377. <Data Name="param1">application-specific</Data>
  10378. <Data Name="param2">Local</Data>
  10379. <Data Name="param3">Activation</Data>
  10380. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10381. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10382. <Data Name="param6">NT AUTHORITY</Data>
  10383. <Data Name="param7">LOCAL SERVICE</Data>
  10384. <Data Name="param8">S-1-5-19</Data>
  10385. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10386. <Data Name="param10">Unavailable</Data>
  10387. <Data Name="param11">Unavailable</Data>
  10388. </EventData>
  10389. </Event>
  10390.  
  10391. Log Name: System
  10392. Source: Microsoft-Windows-DistributedCOM
  10393. Date: 8/23/2016 4:17:41 PM
  10394. Event ID: 10016
  10395. Task Category: None
  10396. Level: Error
  10397. Keywords: Classic
  10398. User: LOCAL SERVICE
  10399. Computer: DESKTOP-D07KK79
  10400. Description:
  10401. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10402. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10403. and APPID
  10404. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10405. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10406. Event Xml:
  10407. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10408. <System>
  10409. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10410. <EventID Qualifiers="0">10016</EventID>
  10411. <Version>0</Version>
  10412. <Level>2</Level>
  10413. <Task>0</Task>
  10414. <Opcode>0</Opcode>
  10415. <Keywords>0x8080000000000000</Keywords>
  10416. <TimeCreated SystemTime="2016-08-23T23:17:41.975602000Z" />
  10417. <EventRecordID>239</EventRecordID>
  10418. <Correlation />
  10419. <Execution ProcessID="860" ThreadID="908" />
  10420. <Channel>System</Channel>
  10421. <Computer>DESKTOP-D07KK79</Computer>
  10422. <Security UserID="S-1-5-19" />
  10423. </System>
  10424. <EventData>
  10425. <Data Name="param1">application-specific</Data>
  10426. <Data Name="param2">Local</Data>
  10427. <Data Name="param3">Activation</Data>
  10428. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10429. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10430. <Data Name="param6">NT AUTHORITY</Data>
  10431. <Data Name="param7">LOCAL SERVICE</Data>
  10432. <Data Name="param8">S-1-5-19</Data>
  10433. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10434. <Data Name="param10">Unavailable</Data>
  10435. <Data Name="param11">Unavailable</Data>
  10436. </EventData>
  10437. </Event>
  10438.  
  10439. Log Name: System
  10440. Source: Microsoft-Windows-DistributedCOM
  10441. Date: 8/23/2016 4:17:41 PM
  10442. Event ID: 10016
  10443. Task Category: None
  10444. Level: Error
  10445. Keywords: Classic
  10446. User: LOCAL SERVICE
  10447. Computer: DESKTOP-D07KK79
  10448. Description:
  10449. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10450. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10451. and APPID
  10452. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10453. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10454. Event Xml:
  10455. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10456. <System>
  10457. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10458. <EventID Qualifiers="0">10016</EventID>
  10459. <Version>0</Version>
  10460. <Level>2</Level>
  10461. <Task>0</Task>
  10462. <Opcode>0</Opcode>
  10463. <Keywords>0x8080000000000000</Keywords>
  10464. <TimeCreated SystemTime="2016-08-23T23:17:41.798586800Z" />
  10465. <EventRecordID>238</EventRecordID>
  10466. <Correlation />
  10467. <Execution ProcessID="860" ThreadID="1944" />
  10468. <Channel>System</Channel>
  10469. <Computer>DESKTOP-D07KK79</Computer>
  10470. <Security UserID="S-1-5-19" />
  10471. </System>
  10472. <EventData>
  10473. <Data Name="param1">application-specific</Data>
  10474. <Data Name="param2">Local</Data>
  10475. <Data Name="param3">Activation</Data>
  10476. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10477. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10478. <Data Name="param6">NT AUTHORITY</Data>
  10479. <Data Name="param7">LOCAL SERVICE</Data>
  10480. <Data Name="param8">S-1-5-19</Data>
  10481. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10482. <Data Name="param10">Unavailable</Data>
  10483. <Data Name="param11">Unavailable</Data>
  10484. </EventData>
  10485. </Event>
  10486.  
  10487. Log Name: System
  10488. Source: Microsoft-Windows-DistributedCOM
  10489. Date: 8/23/2016 4:17:41 PM
  10490. Event ID: 10016
  10491. Task Category: None
  10492. Level: Error
  10493. Keywords: Classic
  10494. User: LOCAL SERVICE
  10495. Computer: DESKTOP-D07KK79
  10496. Description:
  10497. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10498. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10499. and APPID
  10500. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10501. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10502. Event Xml:
  10503. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10504. <System>
  10505. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10506. <EventID Qualifiers="0">10016</EventID>
  10507. <Version>0</Version>
  10508. <Level>2</Level>
  10509. <Task>0</Task>
  10510. <Opcode>0</Opcode>
  10511. <Keywords>0x8080000000000000</Keywords>
  10512. <TimeCreated SystemTime="2016-08-23T23:17:41.144529900Z" />
  10513. <EventRecordID>237</EventRecordID>
  10514. <Correlation />
  10515. <Execution ProcessID="860" ThreadID="1944" />
  10516. <Channel>System</Channel>
  10517. <Computer>DESKTOP-D07KK79</Computer>
  10518. <Security UserID="S-1-5-19" />
  10519. </System>
  10520. <EventData>
  10521. <Data Name="param1">application-specific</Data>
  10522. <Data Name="param2">Local</Data>
  10523. <Data Name="param3">Activation</Data>
  10524. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10525. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10526. <Data Name="param6">NT AUTHORITY</Data>
  10527. <Data Name="param7">LOCAL SERVICE</Data>
  10528. <Data Name="param8">S-1-5-19</Data>
  10529. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10530. <Data Name="param10">Unavailable</Data>
  10531. <Data Name="param11">Unavailable</Data>
  10532. </EventData>
  10533. </Event>
  10534.  
  10535. Log Name: System
  10536. Source: Microsoft-Windows-DistributedCOM
  10537. Date: 8/23/2016 4:17:40 PM
  10538. Event ID: 10016
  10539. Task Category: None
  10540. Level: Error
  10541. Keywords: Classic
  10542. User: LOCAL SERVICE
  10543. Computer: DESKTOP-D07KK79
  10544. Description:
  10545. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10546. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10547. and APPID
  10548. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10549. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10550. Event Xml:
  10551. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10552. <System>
  10553. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10554. <EventID Qualifiers="0">10016</EventID>
  10555. <Version>0</Version>
  10556. <Level>2</Level>
  10557. <Task>0</Task>
  10558. <Opcode>0</Opcode>
  10559. <Keywords>0x8080000000000000</Keywords>
  10560. <TimeCreated SystemTime="2016-08-23T23:17:40.947512700Z" />
  10561. <EventRecordID>236</EventRecordID>
  10562. <Correlation />
  10563. <Execution ProcessID="860" ThreadID="1944" />
  10564. <Channel>System</Channel>
  10565. <Computer>DESKTOP-D07KK79</Computer>
  10566. <Security UserID="S-1-5-19" />
  10567. </System>
  10568. <EventData>
  10569. <Data Name="param1">application-specific</Data>
  10570. <Data Name="param2">Local</Data>
  10571. <Data Name="param3">Activation</Data>
  10572. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10573. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10574. <Data Name="param6">NT AUTHORITY</Data>
  10575. <Data Name="param7">LOCAL SERVICE</Data>
  10576. <Data Name="param8">S-1-5-19</Data>
  10577. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10578. <Data Name="param10">Unavailable</Data>
  10579. <Data Name="param11">Unavailable</Data>
  10580. </EventData>
  10581. </Event>
  10582.  
  10583. Log Name: System
  10584. Source: Microsoft-Windows-DistributedCOM
  10585. Date: 8/23/2016 4:17:40 PM
  10586. Event ID: 10016
  10587. Task Category: None
  10588. Level: Error
  10589. Keywords: Classic
  10590. User: LOCAL SERVICE
  10591. Computer: DESKTOP-D07KK79
  10592. Description:
  10593. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10594. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10595. and APPID
  10596. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10597. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10598. Event Xml:
  10599. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10600. <System>
  10601. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10602. <EventID Qualifiers="0">10016</EventID>
  10603. <Version>0</Version>
  10604. <Level>2</Level>
  10605. <Task>0</Task>
  10606. <Opcode>0</Opcode>
  10607. <Keywords>0x8080000000000000</Keywords>
  10608. <TimeCreated SystemTime="2016-08-23T23:17:40.744495000Z" />
  10609. <EventRecordID>235</EventRecordID>
  10610. <Correlation />
  10611. <Execution ProcessID="860" ThreadID="1944" />
  10612. <Channel>System</Channel>
  10613. <Computer>DESKTOP-D07KK79</Computer>
  10614. <Security UserID="S-1-5-19" />
  10615. </System>
  10616. <EventData>
  10617. <Data Name="param1">application-specific</Data>
  10618. <Data Name="param2">Local</Data>
  10619. <Data Name="param3">Activation</Data>
  10620. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10621. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10622. <Data Name="param6">NT AUTHORITY</Data>
  10623. <Data Name="param7">LOCAL SERVICE</Data>
  10624. <Data Name="param8">S-1-5-19</Data>
  10625. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10626. <Data Name="param10">Unavailable</Data>
  10627. <Data Name="param11">Unavailable</Data>
  10628. </EventData>
  10629. </Event>
  10630.  
  10631. Log Name: System
  10632. Source: Microsoft-Windows-DistributedCOM
  10633. Date: 8/23/2016 4:17:40 PM
  10634. Event ID: 10016
  10635. Task Category: None
  10636. Level: Error
  10637. Keywords: Classic
  10638. User: LOCAL SERVICE
  10639. Computer: DESKTOP-D07KK79
  10640. Description:
  10641. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10642. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10643. and APPID
  10644. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10645. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10646. Event Xml:
  10647. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10648. <System>
  10649. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10650. <EventID Qualifiers="0">10016</EventID>
  10651. <Version>0</Version>
  10652. <Level>2</Level>
  10653. <Task>0</Task>
  10654. <Opcode>0</Opcode>
  10655. <Keywords>0x8080000000000000</Keywords>
  10656. <TimeCreated SystemTime="2016-08-23T23:17:40.485472100Z" />
  10657. <EventRecordID>234</EventRecordID>
  10658. <Correlation />
  10659. <Execution ProcessID="860" ThreadID="1944" />
  10660. <Channel>System</Channel>
  10661. <Computer>DESKTOP-D07KK79</Computer>
  10662. <Security UserID="S-1-5-19" />
  10663. </System>
  10664. <EventData>
  10665. <Data Name="param1">application-specific</Data>
  10666. <Data Name="param2">Local</Data>
  10667. <Data Name="param3">Activation</Data>
  10668. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10669. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10670. <Data Name="param6">NT AUTHORITY</Data>
  10671. <Data Name="param7">LOCAL SERVICE</Data>
  10672. <Data Name="param8">S-1-5-19</Data>
  10673. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10674. <Data Name="param10">Unavailable</Data>
  10675. <Data Name="param11">Unavailable</Data>
  10676. </EventData>
  10677. </Event>
  10678.  
  10679. Log Name: System
  10680. Source: Microsoft-Windows-DistributedCOM
  10681. Date: 8/23/2016 4:17:40 PM
  10682. Event ID: 10016
  10683. Task Category: None
  10684. Level: Error
  10685. Keywords: Classic
  10686. User: LOCAL SERVICE
  10687. Computer: DESKTOP-D07KK79
  10688. Description:
  10689. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10690. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10691. and APPID
  10692. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10693. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10694. Event Xml:
  10695. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10696. <System>
  10697. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10698. <EventID Qualifiers="0">10016</EventID>
  10699. <Version>0</Version>
  10700. <Level>2</Level>
  10701. <Task>0</Task>
  10702. <Opcode>0</Opcode>
  10703. <Keywords>0x8080000000000000</Keywords>
  10704. <TimeCreated SystemTime="2016-08-23T23:17:40.271453400Z" />
  10705. <EventRecordID>233</EventRecordID>
  10706. <Correlation />
  10707. <Execution ProcessID="860" ThreadID="1944" />
  10708. <Channel>System</Channel>
  10709. <Computer>DESKTOP-D07KK79</Computer>
  10710. <Security UserID="S-1-5-19" />
  10711. </System>
  10712. <EventData>
  10713. <Data Name="param1">application-specific</Data>
  10714. <Data Name="param2">Local</Data>
  10715. <Data Name="param3">Activation</Data>
  10716. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10717. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10718. <Data Name="param6">NT AUTHORITY</Data>
  10719. <Data Name="param7">LOCAL SERVICE</Data>
  10720. <Data Name="param8">S-1-5-19</Data>
  10721. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10722. <Data Name="param10">Unavailable</Data>
  10723. <Data Name="param11">Unavailable</Data>
  10724. </EventData>
  10725. </Event>
  10726.  
  10727. Log Name: System
  10728. Source: Microsoft-Windows-DistributedCOM
  10729. Date: 8/23/2016 4:17:40 PM
  10730. Event ID: 10016
  10731. Task Category: None
  10732. Level: Error
  10733. Keywords: Classic
  10734. User: LOCAL SERVICE
  10735. Computer: DESKTOP-D07KK79
  10736. Description:
  10737. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10738. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10739. and APPID
  10740. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10741. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10742. Event Xml:
  10743. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10744. <System>
  10745. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10746. <EventID Qualifiers="0">10016</EventID>
  10747. <Version>0</Version>
  10748. <Level>2</Level>
  10749. <Task>0</Task>
  10750. <Opcode>0</Opcode>
  10751. <Keywords>0x8080000000000000</Keywords>
  10752. <TimeCreated SystemTime="2016-08-23T23:17:40.101438600Z" />
  10753. <EventRecordID>232</EventRecordID>
  10754. <Correlation />
  10755. <Execution ProcessID="860" ThreadID="1944" />
  10756. <Channel>System</Channel>
  10757. <Computer>DESKTOP-D07KK79</Computer>
  10758. <Security UserID="S-1-5-19" />
  10759. </System>
  10760. <EventData>
  10761. <Data Name="param1">application-specific</Data>
  10762. <Data Name="param2">Local</Data>
  10763. <Data Name="param3">Activation</Data>
  10764. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10765. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10766. <Data Name="param6">NT AUTHORITY</Data>
  10767. <Data Name="param7">LOCAL SERVICE</Data>
  10768. <Data Name="param8">S-1-5-19</Data>
  10769. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10770. <Data Name="param10">Unavailable</Data>
  10771. <Data Name="param11">Unavailable</Data>
  10772. </EventData>
  10773. </Event>
  10774.  
  10775. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  10776. Source: Microsoft-Windows-AppModel-Runtime
  10777. Date: 8/23/2016 4:17:39 PM
  10778. Event ID: 69
  10779. Task Category: None
  10780. Level: Error
  10781. Keywords: (70368744177664),Process
  10782. User: SYSTEM
  10783. Computer: DESKTOP-D07KK79
  10784. Description:
  10785. Failed with 0x490 modifying AppModel Runtime status for package Microsoft.Windows.CloudExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy for user DESKTOP-D07KK79\defaultuser0 (current status = 0x0, desired status = 0x20).
  10786. Event Xml:
  10787. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10788. <System>
  10789. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  10790. <EventID>69</EventID>
  10791. <Version>0</Version>
  10792. <Level>2</Level>
  10793. <Task>0</Task>
  10794. <Opcode>0</Opcode>
  10795. <Keywords>0x2000400000000001</Keywords>
  10796. <TimeCreated SystemTime="2016-08-23T23:17:39.957881400Z" />
  10797. <EventRecordID>5</EventRecordID>
  10798. <Correlation ActivityID="{3FC22F77-FD94-0002-2D30-C23F94FDD101}" />
  10799. <Execution ProcessID="968" ThreadID="4980" />
  10800. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  10801. <Computer>DESKTOP-D07KK79</Computer>
  10802. <Security UserID="S-1-5-18" />
  10803. </System>
  10804. <EventData>
  10805. <Data Name="ErrorCode">1168</Data>
  10806. <Data Name="PackageFullName">Microsoft.Windows.CloudExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy</Data>
  10807. <Data Name="User">S-1-5-21-1999763852-2568256858-2669145966-1000</Data>
  10808. <Data Name="DesiredStatus">32</Data>
  10809. <Data Name="CurrentStatus">0</Data>
  10810. </EventData>
  10811. </Event>
  10812.  
  10813. Log Name: System
  10814. Source: Microsoft-Windows-DistributedCOM
  10815. Date: 8/23/2016 4:17:39 PM
  10816. Event ID: 10016
  10817. Task Category: None
  10818. Level: Error
  10819. Keywords: Classic
  10820. User: LOCAL SERVICE
  10821. Computer: DESKTOP-D07KK79
  10822. Description:
  10823. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10824. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10825. and APPID
  10826. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10827. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10828. Event Xml:
  10829. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10830. <System>
  10831. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10832. <EventID Qualifiers="0">10016</EventID>
  10833. <Version>0</Version>
  10834. <Level>2</Level>
  10835. <Task>0</Task>
  10836. <Opcode>0</Opcode>
  10837. <Keywords>0x8080000000000000</Keywords>
  10838. <TimeCreated SystemTime="2016-08-23T23:17:39.927423600Z" />
  10839. <EventRecordID>231</EventRecordID>
  10840. <Correlation />
  10841. <Execution ProcessID="860" ThreadID="1944" />
  10842. <Channel>System</Channel>
  10843. <Computer>DESKTOP-D07KK79</Computer>
  10844. <Security UserID="S-1-5-19" />
  10845. </System>
  10846. <EventData>
  10847. <Data Name="param1">application-specific</Data>
  10848. <Data Name="param2">Local</Data>
  10849. <Data Name="param3">Activation</Data>
  10850. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10851. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10852. <Data Name="param6">NT AUTHORITY</Data>
  10853. <Data Name="param7">LOCAL SERVICE</Data>
  10854. <Data Name="param8">S-1-5-19</Data>
  10855. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10856. <Data Name="param10">Unavailable</Data>
  10857. <Data Name="param11">Unavailable</Data>
  10858. </EventData>
  10859. </Event>
  10860.  
  10861. Log Name: System
  10862. Source: Microsoft-Windows-DistributedCOM
  10863. Date: 8/23/2016 4:17:39 PM
  10864. Event ID: 10016
  10865. Task Category: None
  10866. Level: Error
  10867. Keywords: Classic
  10868. User: LOCAL SERVICE
  10869. Computer: DESKTOP-D07KK79
  10870. Description:
  10871. The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
  10872. {D63B10C5-BB46-4990-A94F-E40B9D520160}
  10873. and APPID
  10874. {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
  10875. to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
  10876. Event Xml:
  10877. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10878. <System>
  10879. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  10880. <EventID Qualifiers="0">10016</EventID>
  10881. <Version>0</Version>
  10882. <Level>2</Level>
  10883. <Task>0</Task>
  10884. <Opcode>0</Opcode>
  10885. <Keywords>0x8080000000000000</Keywords>
  10886. <TimeCreated SystemTime="2016-08-23T23:17:39.329371100Z" />
  10887. <EventRecordID>230</EventRecordID>
  10888. <Correlation />
  10889. <Execution ProcessID="860" ThreadID="1944" />
  10890. <Channel>System</Channel>
  10891. <Computer>DESKTOP-D07KK79</Computer>
  10892. <Security UserID="S-1-5-19" />
  10893. </System>
  10894. <EventData>
  10895. <Data Name="param1">application-specific</Data>
  10896. <Data Name="param2">Local</Data>
  10897. <Data Name="param3">Activation</Data>
  10898. <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
  10899. <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
  10900. <Data Name="param6">NT AUTHORITY</Data>
  10901. <Data Name="param7">LOCAL SERVICE</Data>
  10902. <Data Name="param8">S-1-5-19</Data>
  10903. <Data Name="param9">LocalHost (Using LRPC)</Data>
  10904. <Data Name="param10">Unavailable</Data>
  10905. <Data Name="param11">Unavailable</Data>
  10906. </EventData>
  10907. </Event>
  10908.  
  10909. Log Name: Application
  10910. Source: Microsoft-Windows-Search
  10911. Date: 8/23/2016 4:17:23 PM
  10912. Event ID: 1008
  10913. Task Category: Search service
  10914. Level: Warning
  10915. Keywords: Classic
  10916. User: N/A
  10917. Computer: DESKTOP-D07KK79
  10918. Description:
  10919. The Windows Search Service is starting up and attempting to remove the old search index {Reason: Full Index Reset}.
  10920.  
  10921. Event Xml:
  10922. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10923. <System>
  10924. <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
  10925. <EventID Qualifiers="32768">1008</EventID>
  10926. <Version>0</Version>
  10927. <Level>3</Level>
  10928. <Task>1</Task>
  10929. <Opcode>0</Opcode>
  10930. <Keywords>0x80000000000000</Keywords>
  10931. <TimeCreated SystemTime="2016-08-23T23:17:23.802116800Z" />
  10932. <EventRecordID>25</EventRecordID>
  10933. <Correlation />
  10934. <Execution ProcessID="0" ThreadID="0" />
  10935. <Channel>Application</Channel>
  10936. <Computer>DESKTOP-D07KK79</Computer>
  10937. <Security />
  10938. </System>
  10939. <EventData>
  10940. <Data Name="ExtraInfo">
  10941. </Data>
  10942. <Data Name="Reason">Full Index Reset</Data>
  10943. </EventData>
  10944. </Event>
  10945.  
  10946. Log Name: System
  10947. Source: Microsoft-Windows-Time-Service
  10948. Date: 8/23/2016 4:16:22 PM
  10949. Event ID: 134
  10950. Task Category: None
  10951. Level: Warning
  10952. Keywords:
  10953. User: LOCAL SERVICE
  10954. Computer: DESKTOP-D07KK79
  10955. Description:
  10956. NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
  10957. Event Xml:
  10958. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10959. <System>
  10960. <Provider Name="Microsoft-Windows-Time-Service" Guid="{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}" />
  10961. <EventID>134</EventID>
  10962. <Version>0</Version>
  10963. <Level>3</Level>
  10964. <Task>0</Task>
  10965. <Opcode>0</Opcode>
  10966. <Keywords>0x8000000000000000</Keywords>
  10967. <TimeCreated SystemTime="2016-08-23T23:16:22.637490000Z" />
  10968. <EventRecordID>213</EventRecordID>
  10969. <Correlation />
  10970. <Execution ProcessID="1476" ThreadID="1556" />
  10971. <Channel>System</Channel>
  10972. <Computer>DESKTOP-D07KK79</Computer>
  10973. <Security UserID="S-1-5-19" />
  10974. </System>
  10975. <EventData Name="TMP_EVENT_MANUAL_PEER_DNS_ERROR">
  10976. <Data Name="ErrorMessage">No such host is known. (0x80072AF9)</Data>
  10977. <Data Name="RetryMinutes">15</Data>
  10978. <Data Name="DomainPeer">time.windows.com,0x9</Data>
  10979. </EventData>
  10980. </Event>
  10981.  
  10982. Log Name: System
  10983. Source: Microsoft-Windows-Time-Service
  10984. Date: 8/23/2016 4:16:21 PM
  10985. Event ID: 134
  10986. Task Category: None
  10987. Level: Warning
  10988. Keywords:
  10989. User: LOCAL SERVICE
  10990. Computer: DESKTOP-D07KK79
  10991. Description:
  10992. NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on 'time.windows.com,0x9'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
  10993. Event Xml:
  10994. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  10995. <System>
  10996. <Provider Name="Microsoft-Windows-Time-Service" Guid="{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}" />
  10997. <EventID>134</EventID>
  10998. <Version>0</Version>
  10999. <Level>3</Level>
  11000. <Task>0</Task>
  11001. <Opcode>0</Opcode>
  11002. <Keywords>0x8000000000000000</Keywords>
  11003. <TimeCreated SystemTime="2016-08-23T23:16:21.135379600Z" />
  11004. <EventRecordID>209</EventRecordID>
  11005. <Correlation />
  11006. <Execution ProcessID="1476" ThreadID="1556" />
  11007. <Channel>System</Channel>
  11008. <Computer>DESKTOP-D07KK79</Computer>
  11009. <Security UserID="S-1-5-19" />
  11010. </System>
  11011. <EventData Name="TMP_EVENT_MANUAL_PEER_DNS_ERROR">
  11012. <Data Name="ErrorMessage">No such host is known. (0x80072AF9)</Data>
  11013. <Data Name="RetryMinutes">15</Data>
  11014. <Data Name="DomainPeer">time.windows.com,0x9</Data>
  11015. </EventData>
  11016. </Event>
  11017.  
  11018. Log Name: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
  11019. Source: Microsoft-Windows-DeviceManagement-Pushrouter
  11020. Date: 8/23/2016 4:15:55 PM
  11021. Event ID: 506
  11022. Task Category: None
  11023. Level: Error
  11024. Keywords:
  11025. User: SYSTEM
  11026. Computer: DESKTOP-D07KK79
  11027. Description:
  11028. DmWapPushService: Failed to register WNF with EventAggregator for WAP messages received by SMS Router. Result: (0xC0020036).
  11029. Event Xml:
  11030. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11031. <System>
  11032. <Provider Name="Microsoft-Windows-DeviceManagement-Pushrouter" Guid="{F1201B5A-E170-42B6-8D20-B57AC57E6416}" />
  11033. <EventID>506</EventID>
  11034. <Version>0</Version>
  11035. <Level>2</Level>
  11036. <Task>0</Task>
  11037. <Opcode>0</Opcode>
  11038. <Keywords>0x8000000000000000</Keywords>
  11039. <TimeCreated SystemTime="2016-08-23T23:15:55.404442900Z" />
  11040. <EventRecordID>42</EventRecordID>
  11041. <Correlation />
  11042. <Execution ProcessID="1012" ThreadID="388" />
  11043. <Channel>Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin</Channel>
  11044. <Computer>DESKTOP-D07KK79</Computer>
  11045. <Security UserID="S-1-5-18" />
  11046. </System>
  11047. <EventData>
  11048. <Data Name="HexInt1">0xc0020036</Data>
  11049. </EventData>
  11050. </Event>
  11051.  
  11052. Log Name: System
  11053. Source: Microsoft-Windows-Kernel-PnP
  11054. Date: 8/23/2016 4:15:46 PM
  11055. Event ID: 219
  11056. Task Category: (212)
  11057. Level: Warning
  11058. Keywords:
  11059. User: SYSTEM
  11060. Computer: DESKTOP-D07KK79
  11061. Description:
  11062. The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&0.
  11063. Event Xml:
  11064. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11065. <System>
  11066. <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
  11067. <EventID>219</EventID>
  11068. <Version>0</Version>
  11069. <Level>3</Level>
  11070. <Task>212</Task>
  11071. <Opcode>0</Opcode>
  11072. <Keywords>0x8000000000000000</Keywords>
  11073. <TimeCreated SystemTime="2016-08-23T23:15:46.578956700Z" />
  11074. <EventRecordID>191</EventRecordID>
  11075. <Correlation />
  11076. <Execution ProcessID="4" ThreadID="348" />
  11077. <Channel>System</Channel>
  11078. <Computer>DESKTOP-D07KK79</Computer>
  11079. <Security UserID="S-1-5-18" />
  11080. </System>
  11081. <EventData>
  11082. <Data Name="DriverNameLength">24</Data>
  11083. <Data Name="DriverName">ACPI\PNP0A0A\2&amp;daba3ff&amp;0</Data>
  11084. <Data Name="Status">3221226341</Data>
  11085. <Data Name="FailureNameLength">14</Data>
  11086. <Data Name="FailureName">\Driver\WUDFRd</Data>
  11087. <Data Name="Version">0</Data>
  11088. </EventData>
  11089. </Event>
  11090.  
  11091. Log Name: System
  11092. Source: Service Control Manager
  11093. Date: 8/23/2016 4:15:08 PM
  11094. Event ID: 7024
  11095. Task Category: None
  11096. Level: Error
  11097. Keywords: Classic
  11098. User: N/A
  11099. Computer: DESKTOP-D07KK79
  11100. Description:
  11101. The Background Intelligent Transfer Service service terminated with the following service-specific error:
  11102. The media is write protected.
  11103. Event Xml:
  11104. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11105. <System>
  11106. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11107. <EventID Qualifiers="49152">7024</EventID>
  11108. <Version>0</Version>
  11109. <Level>2</Level>
  11110. <Task>0</Task>
  11111. <Opcode>0</Opcode>
  11112. <Keywords>0x8080000000000000</Keywords>
  11113. <TimeCreated SystemTime="2016-08-23T23:15:08.678755500Z" />
  11114. <EventRecordID>169</EventRecordID>
  11115. <Correlation />
  11116. <Execution ProcessID="720" ThreadID="1512" />
  11117. <Channel>System</Channel>
  11118. <Computer>DESKTOP-D07KK79</Computer>
  11119. <Security />
  11120. </System>
  11121. <EventData>
  11122. <Data Name="param1">Background Intelligent Transfer Service</Data>
  11123. <Data Name="param2">%%2147942419</Data>
  11124. <Binary>42004900540053000000</Binary>
  11125. </EventData>
  11126. </Event>
  11127.  
  11128. Log Name: System
  11129. Source: Microsoft-Windows-Bits-Client
  11130. Date: 8/23/2016 4:15:08 PM
  11131. Event ID: 16392
  11132. Task Category: None
  11133. Level: Error
  11134. Keywords:
  11135. User: SYSTEM
  11136. Computer: DESKTOP-D07KK79
  11137. Description:
  11138. The BITS service failed to start. Error 0x80070013.
  11139. Event Xml:
  11140. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11141. <System>
  11142. <Provider Name="Microsoft-Windows-Bits-Client" Guid="{EF1CC15B-46C1-414E-BB95-E76B077BD51E}" />
  11143. <EventID>16392</EventID>
  11144. <Version>0</Version>
  11145. <Level>2</Level>
  11146. <Task>0</Task>
  11147. <Opcode>0</Opcode>
  11148. <Keywords>0x8000000000000000</Keywords>
  11149. <TimeCreated SystemTime="2016-08-23T23:15:08.679510300Z" />
  11150. <EventRecordID>168</EventRecordID>
  11151. <Correlation />
  11152. <Execution ProcessID="96" ThreadID="1052" />
  11153. <Channel>System</Channel>
  11154. <Computer>DESKTOP-D07KK79</Computer>
  11155. <Security UserID="S-1-5-18" />
  11156. </System>
  11157. <EventData>
  11158. <Data Name="ErrorCode">2147942419</Data>
  11159. </EventData>
  11160. </Event>
  11161.  
  11162. Log Name: System
  11163. Source: Service Control Manager
  11164. Date: 8/23/2016 4:15:08 PM
  11165. Event ID: 7023
  11166. Task Category: None
  11167. Level: Error
  11168. Keywords: Classic
  11169. User: N/A
  11170. Computer: WIN-KUKHEJE7E8R
  11171. Description:
  11172. The Network Connection Broker service terminated with the following error:
  11173. A device attached to the system is not functioning.
  11174. Event Xml:
  11175. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11176. <System>
  11177. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11178. <EventID Qualifiers="49152">7023</EventID>
  11179. <Version>0</Version>
  11180. <Level>2</Level>
  11181. <Task>0</Task>
  11182. <Opcode>0</Opcode>
  11183. <Keywords>0x8080000000000000</Keywords>
  11184. <TimeCreated SystemTime="2016-08-23T23:15:08.364728100Z" />
  11185. <EventRecordID>162</EventRecordID>
  11186. <Correlation />
  11187. <Execution ProcessID="720" ThreadID="800" />
  11188. <Channel>System</Channel>
  11189. <Computer>WIN-KUKHEJE7E8R</Computer>
  11190. <Security />
  11191. </System>
  11192. <EventData>
  11193. <Data Name="param1">Network Connection Broker</Data>
  11194. <Data Name="param2">%%31</Data>
  11195. <Binary>4E006300620053006500720076006900630065000000</Binary>
  11196. </EventData>
  11197. </Event>
  11198.  
  11199. Log Name: System
  11200. Source: Microsoft-Windows-DistributedCOM
  11201. Date: 8/23/2016 4:15:08 PM
  11202. Event ID: 10010
  11203. Task Category: None
  11204. Level: Error
  11205. Keywords: Classic
  11206. User: NETWORK SERVICE
  11207. Computer: WIN-KUKHEJE7E8R
  11208. Description:
  11209. The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
  11210. Event Xml:
  11211. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11212. <System>
  11213. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  11214. <EventID Qualifiers="0">10010</EventID>
  11215. <Version>0</Version>
  11216. <Level>2</Level>
  11217. <Task>0</Task>
  11218. <Opcode>0</Opcode>
  11219. <Keywords>0x8080000000000000</Keywords>
  11220. <TimeCreated SystemTime="2016-08-23T23:15:08.303722800Z" />
  11221. <EventRecordID>161</EventRecordID>
  11222. <Correlation />
  11223. <Execution ProcessID="912" ThreadID="1084" />
  11224. <Channel>System</Channel>
  11225. <Computer>WIN-KUKHEJE7E8R</Computer>
  11226. <Security UserID="S-1-5-20" />
  11227. </System>
  11228. <EventData>
  11229. <Data Name="param1">{A47979D2-C419-11D9-A5B4-001185AD2B89}</Data>
  11230. </EventData>
  11231. </Event>
  11232.  
  11233. Log Name: System
  11234. Source: Service Control Manager
  11235. Date: 8/23/2016 4:15:01 PM
  11236. Event ID: 7043
  11237. Task Category: None
  11238. Level: Error
  11239. Keywords: Classic
  11240. User: N/A
  11241. Computer: WIN-KUKHEJE7E8R
  11242. Description:
  11243. The Delivery Optimization service did not shut down properly after receiving a preshutdown control.
  11244. Event Xml:
  11245. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11246. <System>
  11247. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11248. <EventID Qualifiers="49152">7043</EventID>
  11249. <Version>0</Version>
  11250. <Level>2</Level>
  11251. <Task>0</Task>
  11252. <Opcode>0</Opcode>
  11253. <Keywords>0x8080000000000000</Keywords>
  11254. <TimeCreated SystemTime="2016-08-23T23:15:01.354121100Z" />
  11255. <EventRecordID>158</EventRecordID>
  11256. <Correlation ActivityID="{99F045C8-FD93-0002-AD46-F09993FDD101}" />
  11257. <Execution ProcessID="720" ThreadID="800" />
  11258. <Channel>System</Channel>
  11259. <Computer>WIN-KUKHEJE7E8R</Computer>
  11260. <Security />
  11261. </System>
  11262. <EventData>
  11263. <Data Name="param1">Delivery Optimization</Data>
  11264. <Binary>44006F005300760063000000</Binary>
  11265. </EventData>
  11266. </Event>
  11267.  
  11268. Log Name: System
  11269. Source: Microsoft-Windows-DistributedCOM
  11270. Date: 8/23/2016 4:14:55 PM
  11271. Event ID: 10010
  11272. Task Category: None
  11273. Level: Error
  11274. Keywords: Classic
  11275. User: LOCAL SERVICE
  11276. Computer: WIN-KUKHEJE7E8R
  11277. Description:
  11278. The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.
  11279. Event Xml:
  11280. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11281. <System>
  11282. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  11283. <EventID Qualifiers="0">10010</EventID>
  11284. <Version>0</Version>
  11285. <Level>2</Level>
  11286. <Task>0</Task>
  11287. <Opcode>0</Opcode>
  11288. <Keywords>0x8080000000000000</Keywords>
  11289. <TimeCreated SystemTime="2016-08-23T23:14:55.371603200Z" />
  11290. <EventRecordID>157</EventRecordID>
  11291. <Correlation />
  11292. <Execution ProcessID="912" ThreadID="2420" />
  11293. <Channel>System</Channel>
  11294. <Computer>WIN-KUKHEJE7E8R</Computer>
  11295. <Security UserID="S-1-5-19" />
  11296. </System>
  11297. <EventData>
  11298. <Data Name="param1">{4991D34B-80A1-4291-83B6-3328366B9097}</Data>
  11299. </EventData>
  11300. </Event>
  11301.  
  11302. Log Name: Application
  11303. Source: SecurityCenter
  11304. Date: 8/23/2016 4:13:48 PM
  11305. Event ID: 16
  11306. Task Category: None
  11307. Level: Error
  11308. Keywords: Classic
  11309. User: N/A
  11310. Computer: WIN-KUKHEJE7E8R
  11311. Description:
  11312. Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_ON (error 02000000).
  11313. Event Xml:
  11314. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11315. <System>
  11316. <Provider Name="SecurityCenter" />
  11317. <EventID Qualifiers="49152">16</EventID>
  11318. <Level>2</Level>
  11319. <Task>0</Task>
  11320. <Keywords>0x80000000000000</Keywords>
  11321. <TimeCreated SystemTime="2016-08-23T23:13:48.198788000Z" />
  11322. <EventRecordID>8</EventRecordID>
  11323. <Channel>Application</Channel>
  11324. <Computer>WIN-KUKHEJE7E8R</Computer>
  11325. <Security />
  11326. </System>
  11327. <EventData>
  11328. <Data>Windows Defender</Data>
  11329. <Data>SECURITY_PRODUCT_STATE_ON</Data>
  11330. <Binary>02000000</Binary>
  11331. </EventData>
  11332. </Event>
  11333.  
  11334. Log Name: Application
  11335. Source: SecurityCenter
  11336. Date: 8/23/2016 4:13:48 PM
  11337. Event ID: 16
  11338. Task Category: None
  11339. Level: Error
  11340. Keywords: Classic
  11341. User: N/A
  11342. Computer: WIN-KUKHEJE7E8R
  11343. Description:
  11344. Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_ON (error 02000000).
  11345. Event Xml:
  11346. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11347. <System>
  11348. <Provider Name="SecurityCenter" />
  11349. <EventID Qualifiers="49152">16</EventID>
  11350. <Level>2</Level>
  11351. <Task>0</Task>
  11352. <Keywords>0x80000000000000</Keywords>
  11353. <TimeCreated SystemTime="2016-08-23T23:13:48.111780500Z" />
  11354. <EventRecordID>6</EventRecordID>
  11355. <Channel>Application</Channel>
  11356. <Computer>WIN-KUKHEJE7E8R</Computer>
  11357. <Security />
  11358. </System>
  11359. <EventData>
  11360. <Data>Windows Defender</Data>
  11361. <Data>SECURITY_PRODUCT_STATE_ON</Data>
  11362. <Binary>02000000</Binary>
  11363. </EventData>
  11364. </Event>
  11365.  
  11366. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  11367. Source: Microsoft-Windows-AppModel-Runtime
  11368. Date: 8/23/2016 4:13:45 PM
  11369. Event ID: 21
  11370. Task Category: None
  11371. Level: Error
  11372. Keywords: (70368744177664),AppContainer
  11373. User: SYSTEM
  11374. Computer: WIN-KUKHEJE7E8R
  11375. Description:
  11376. CreateAppContainerProfile failed for AppContainer Microsoft.Advertising.Xaml_8wekyb3d8bbwe with error 0x8007000A.
  11377. Event Xml:
  11378. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11379. <System>
  11380. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  11381. <EventID>21</EventID>
  11382. <Version>0</Version>
  11383. <Level>2</Level>
  11384. <Task>0</Task>
  11385. <Opcode>0</Opcode>
  11386. <Keywords>0x2000400000000002</Keywords>
  11387. <TimeCreated SystemTime="2016-08-23T23:13:45.207306600Z" />
  11388. <EventRecordID>2</EventRecordID>
  11389. <Correlation />
  11390. <Execution ProcessID="412" ThreadID="928" />
  11391. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  11392. <Computer>WIN-KUKHEJE7E8R</Computer>
  11393. <Security UserID="S-1-5-18" />
  11394. </System>
  11395. <EventData>
  11396. <Data Name="ErrorCode">2147942410</Data>
  11397. <Data Name="Context">Microsoft.Advertising.Xaml_8wekyb3d8bbwe</Data>
  11398. </EventData>
  11399. </Event>
  11400.  
  11401. Log Name: Microsoft-Windows-AppModel-Runtime/Admin
  11402. Source: Microsoft-Windows-AppModel-Runtime
  11403. Date: 8/23/2016 4:13:45 PM
  11404. Event ID: 37
  11405. Task Category: None
  11406. Level: Error
  11407. Keywords: AppContainer
  11408. User: SYSTEM
  11409. Computer: WIN-KUKHEJE7E8R
  11410. Description:
  11411. App Container profile failed with error 0x800700B7 because it was unable to register the AppContainer SID.
  11412. Event Xml:
  11413. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11414. <System>
  11415. <Provider Name="Microsoft-Windows-AppModel-Runtime" Guid="{F1EF270A-0D32-4352-BA52-DBAB41E1D859}" />
  11416. <EventID>37</EventID>
  11417. <Version>0</Version>
  11418. <Level>2</Level>
  11419. <Task>0</Task>
  11420. <Opcode>0</Opcode>
  11421. <Keywords>0x2000000000000002</Keywords>
  11422. <TimeCreated SystemTime="2016-08-23T23:13:45.207302100Z" />
  11423. <EventRecordID>1</EventRecordID>
  11424. <Correlation />
  11425. <Execution ProcessID="412" ThreadID="928" />
  11426. <Channel>Microsoft-Windows-AppModel-Runtime/Admin</Channel>
  11427. <Computer>WIN-KUKHEJE7E8R</Computer>
  11428. <Security UserID="S-1-5-18" />
  11429. </System>
  11430. <EventData>
  11431. <Data Name="ErrorCode">2147942583</Data>
  11432. </EventData>
  11433. </Event>
  11434.  
  11435. Log Name: System
  11436. Source: Service Control Manager
  11437. Date: 8/23/2016 4:13:38 PM
  11438. Event ID: 7023
  11439. Task Category: None
  11440. Level: Error
  11441. Keywords: Classic
  11442. User: N/A
  11443. Computer: WIN-KUKHEJE7E8R
  11444. Description:
  11445. The Network List Service service terminated with the following error:
  11446. The device is not ready.
  11447. Event Xml:
  11448. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11449. <System>
  11450. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11451. <EventID Qualifiers="49152">7023</EventID>
  11452. <Version>0</Version>
  11453. <Level>2</Level>
  11454. <Task>0</Task>
  11455. <Opcode>0</Opcode>
  11456. <Keywords>0x8080000000000000</Keywords>
  11457. <TimeCreated SystemTime="2016-08-23T23:13:38.302931300Z" />
  11458. <EventRecordID>148</EventRecordID>
  11459. <Correlation />
  11460. <Execution ProcessID="720" ThreadID="800" />
  11461. <Channel>System</Channel>
  11462. <Computer>WIN-KUKHEJE7E8R</Computer>
  11463. <Security />
  11464. </System>
  11465. <EventData>
  11466. <Data Name="param1">Network List Service</Data>
  11467. <Data Name="param2">%%21</Data>
  11468. <Binary>6E0065007400700072006F0066006D000000</Binary>
  11469. </EventData>
  11470. </Event>
  11471.  
  11472. Log Name: System
  11473. Source: Microsoft-Windows-DistributedCOM
  11474. Date: 8/23/2016 4:13:38 PM
  11475. Event ID: 10010
  11476. Task Category: None
  11477. Level: Error
  11478. Keywords: Classic
  11479. User: SYSTEM
  11480. Computer: WIN-KUKHEJE7E8R
  11481. Description:
  11482. The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
  11483. Event Xml:
  11484. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11485. <System>
  11486. <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  11487. <EventID Qualifiers="0">10010</EventID>
  11488. <Version>0</Version>
  11489. <Level>2</Level>
  11490. <Task>0</Task>
  11491. <Opcode>0</Opcode>
  11492. <Keywords>0x8080000000000000</Keywords>
  11493. <TimeCreated SystemTime="2016-08-23T23:13:38.300930800Z" />
  11494. <EventRecordID>147</EventRecordID>
  11495. <Correlation />
  11496. <Execution ProcessID="912" ThreadID="948" />
  11497. <Channel>System</Channel>
  11498. <Computer>WIN-KUKHEJE7E8R</Computer>
  11499. <Security UserID="S-1-5-18" />
  11500. </System>
  11501. <EventData>
  11502. <Data Name="param1">{A47979D2-C419-11D9-A5B4-001185AD2B89}</Data>
  11503. </EventData>
  11504. </Event>
  11505.  
  11506. Log Name: System
  11507. Source: Service Control Manager
  11508. Date: 8/23/2016 4:11:43 PM
  11509. Event ID: 7023
  11510. Task Category: None
  11511. Level: Error
  11512. Keywords: Classic
  11513. User: N/A
  11514. Computer: WIN-KUKHEJE7E8R
  11515. Description:
  11516. The IP Helper service terminated with the following error:
  11517. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  11518. Event Xml:
  11519. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11520. <System>
  11521. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11522. <EventID Qualifiers="49152">7023</EventID>
  11523. <Version>0</Version>
  11524. <Level>2</Level>
  11525. <Task>0</Task>
  11526. <Opcode>0</Opcode>
  11527. <Keywords>0x8080000000000000</Keywords>
  11528. <TimeCreated SystemTime="2016-08-23T23:11:43.227111400Z" />
  11529. <EventRecordID>51</EventRecordID>
  11530. <Correlation />
  11531. <Execution ProcessID="720" ThreadID="804" />
  11532. <Channel>System</Channel>
  11533. <Computer>WIN-KUKHEJE7E8R</Computer>
  11534. <Security />
  11535. </System>
  11536. <EventData>
  11537. <Data Name="param1">IP Helper</Data>
  11538. <Data Name="param2">%%1058</Data>
  11539. <Binary>6900700068006C0070007300760063000000</Binary>
  11540. </EventData>
  11541. </Event>
  11542.  
  11543. Log Name: Microsoft-Windows-SMBWitnessClient/Admin
  11544. Source: Microsoft-Windows-SMBWitnessClient
  11545. Date: 8/23/2016 4:11:38 PM
  11546. Event ID: 1
  11547. Task Category: None
  11548. Level: Error
  11549. Keywords:
  11550. User: NETWORK SERVICE
  11551. Computer: WIN-KUKHEJE7E8R
  11552. Description:
  11553. Witness Client initialization failed with error (The system cannot find the file specified.)
  11554. Event Xml:
  11555. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11556. <System>
  11557. <Provider Name="Microsoft-Windows-SMBWitnessClient" Guid="{32254F6C-AA33-46F0-A5E3-1CBCC74BF683}" />
  11558. <EventID>1</EventID>
  11559. <Version>0</Version>
  11560. <Level>2</Level>
  11561. <Task>0</Task>
  11562. <Opcode>0</Opcode>
  11563. <Keywords>0x8000000000000000</Keywords>
  11564. <TimeCreated SystemTime="2016-08-23T23:11:38.958473500Z" />
  11565. <EventRecordID>1</EventRecordID>
  11566. <Correlation />
  11567. <Execution ProcessID="1632" ThreadID="1884" />
  11568. <Channel>Microsoft-Windows-SMBWitnessClient/Admin</Channel>
  11569. <Computer>WIN-KUKHEJE7E8R</Computer>
  11570. <Security UserID="S-1-5-20" />
  11571. </System>
  11572. <EventData>
  11573. <Data Name="ErrorCode">2</Data>
  11574. </EventData>
  11575. </Event>
  11576.  
  11577. Log Name: System
  11578. Source: Service Control Manager
  11579. Date: 8/23/2016 4:11:38 PM
  11580. Event ID: 7023
  11581. Task Category: None
  11582. Level: Error
  11583. Keywords: Classic
  11584. User: N/A
  11585. Computer: WIN-KUKHEJE7E8R
  11586. Description:
  11587. The netprofm service terminated with the following error:
  11588. The device is not ready.
  11589. Event Xml:
  11590. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11591. <System>
  11592. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11593. <EventID Qualifiers="49152">7023</EventID>
  11594. <Version>0</Version>
  11595. <Level>2</Level>
  11596. <Task>0</Task>
  11597. <Opcode>0</Opcode>
  11598. <Keywords>0x8080000000000000</Keywords>
  11599. <TimeCreated SystemTime="2016-08-23T23:11:38.242354900Z" />
  11600. <EventRecordID>48</EventRecordID>
  11601. <Correlation />
  11602. <Execution ProcessID="720" ThreadID="1348" />
  11603. <Channel>System</Channel>
  11604. <Computer>WIN-KUKHEJE7E8R</Computer>
  11605. <Security />
  11606. </System>
  11607. <EventData>
  11608. <Data Name="param1">netprofm</Data>
  11609. <Data Name="param2">%%21</Data>
  11610. <Binary>6E0065007400700072006F0066006D000000</Binary>
  11611. </EventData>
  11612. </Event>
  11613.  
  11614. Log Name: System
  11615. Source: Service Control Manager
  11616. Date: 8/23/2016 4:11:37 PM
  11617. Event ID: 7023
  11618. Task Category: None
  11619. Level: Error
  11620. Keywords: Classic
  11621. User: N/A
  11622. Computer: WIN-KUKHEJE7E8R
  11623. Description:
  11624. The Spooler service terminated with the following error:
  11625. Ran out of memory
  11626. Event Xml:
  11627. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11628. <System>
  11629. <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
  11630. <EventID Qualifiers="49152">7023</EventID>
  11631. <Version>0</Version>
  11632. <Level>2</Level>
  11633. <Task>0</Task>
  11634. <Opcode>0</Opcode>
  11635. <Keywords>0x8080000000000000</Keywords>
  11636. <TimeCreated SystemTime="2016-08-23T23:11:37.820447600Z" />
  11637. <EventRecordID>47</EventRecordID>
  11638. <Correlation />
  11639. <Execution ProcessID="720" ThreadID="1348" />
  11640. <Channel>System</Channel>
  11641. <Computer>WIN-KUKHEJE7E8R</Computer>
  11642. <Security />
  11643. </System>
  11644. <EventData>
  11645. <Data Name="param1">Spooler</Data>
  11646. <Data Name="param2">%%2147942414</Data>
  11647. <Binary>530070006F006F006C00650072000000</Binary>
  11648. </EventData>
  11649. </Event>
  11650.  
  11651. Log Name: System
  11652. Source: Microsoft-Windows-TaskScheduler
  11653. Date: 8/23/2016 4:11:37 PM
  11654. Event ID: 404
  11655. Task Category: Service RPC error
  11656. Level: Critical
  11657. Keywords:
  11658. User: SYSTEM
  11659. Computer: WIN-KUKHEJE7E8R
  11660. Description:
  11661. Task Scheduler service has encountered RPC initialization error in "RpcServerUseProtseq:ncacn_ip_tcp". Additional Data: Error Value: 14.
  11662. Event Xml:
  11663. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11664. <System>
  11665. <Provider Name="Microsoft-Windows-TaskScheduler" Guid="{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}" />
  11666. <EventID>404</EventID>
  11667. <Version>0</Version>
  11668. <Level>1</Level>
  11669. <Task>404</Task>
  11670. <Opcode>0</Opcode>
  11671. <Keywords>0x4000000000000000</Keywords>
  11672. <TimeCreated SystemTime="2016-08-23T23:11:37.767727500Z" />
  11673. <EventRecordID>46</EventRecordID>
  11674. <Correlation />
  11675. <Execution ProcessID="96" ThreadID="1592" />
  11676. <Channel>System</Channel>
  11677. <Computer>WIN-KUKHEJE7E8R</Computer>
  11678. <Security UserID="S-1-5-18" />
  11679. </System>
  11680. <EventData Name="RpcInitializationError">
  11681. <Data Name="ErrorDescription">RpcServerUseProtseq:ncacn_ip_tcp</Data>
  11682. <Data Name="ResultCode">14</Data>
  11683. </EventData>
  11684. </Event>
  11685.  
  11686. Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
  11687. Source: Microsoft-Windows-Kernel-EventTracing
  11688. Date: 8/23/2016 4:11:34 PM
  11689. Event ID: 2
  11690. Task Category: Session
  11691. Level: Error
  11692. Keywords: Session
  11693. User: SYSTEM
  11694. Computer: WIN-KUKHEJE7E8R
  11695. Description:
  11696. Session "SceSetup" failed to start with the following error: 0xC0000035
  11697. Event Xml:
  11698. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11699. <System>
  11700. <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
  11701. <EventID>2</EventID>
  11702. <Version>0</Version>
  11703. <Level>2</Level>
  11704. <Task>2</Task>
  11705. <Opcode>12</Opcode>
  11706. <Keywords>0x8000000000000010</Keywords>
  11707. <TimeCreated SystemTime="2016-08-23T23:11:34.060278600Z" />
  11708. <EventRecordID>3</EventRecordID>
  11709. <Correlation />
  11710. <Execution ProcessID="1216" ThreadID="1220" />
  11711. <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
  11712. <Computer>WIN-KUKHEJE7E8R</Computer>
  11713. <Security UserID="S-1-5-18" />
  11714. </System>
  11715. <EventData>
  11716. <Data Name="SessionName">SceSetup</Data>
  11717. <Data Name="FileName">
  11718. </Data>
  11719. <Data Name="ErrorCode">3221225525</Data>
  11720. <Data Name="LoggingMode">268435461</Data>
  11721. </EventData>
  11722. </Event>
  11723.  
  11724. Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
  11725. Source: Microsoft-Windows-Kernel-EventTracing
  11726. Date: 8/23/2016 4:11:26 PM
  11727. Event ID: 2
  11728. Task Category: Session
  11729. Level: Error
  11730. Keywords: Session
  11731. User: SYSTEM
  11732. Computer: WIN-KUKHEJE7E8R
  11733. Description:
  11734. Session "SceSetup" failed to start with the following error: 0xC0000035
  11735. Event Xml:
  11736. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11737. <System>
  11738. <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
  11739. <EventID>2</EventID>
  11740. <Version>0</Version>
  11741. <Level>2</Level>
  11742. <Task>2</Task>
  11743. <Opcode>12</Opcode>
  11744. <Keywords>0x8000000000000010</Keywords>
  11745. <TimeCreated SystemTime="2016-08-23T23:11:26.914626100Z" />
  11746. <EventRecordID>2</EventRecordID>
  11747. <Correlation />
  11748. <Execution ProcessID="1132" ThreadID="1136" />
  11749. <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
  11750. <Computer>WIN-KUKHEJE7E8R</Computer>
  11751. <Security UserID="S-1-5-18" />
  11752. </System>
  11753. <EventData>
  11754. <Data Name="SessionName">SceSetup</Data>
  11755. <Data Name="FileName">
  11756. </Data>
  11757. <Data Name="ErrorCode">3221225525</Data>
  11758. <Data Name="LoggingMode">268435461</Data>
  11759. </EventData>
  11760. </Event>
  11761.  
  11762. Log Name: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
  11763. Source: Microsoft-Windows-DeviceManagement-Pushrouter
  11764. Date: 8/23/2016 4:11:23 PM
  11765. Event ID: 506
  11766. Task Category: None
  11767. Level: Error
  11768. Keywords:
  11769. User: SYSTEM
  11770. Computer: WIN-KUKHEJE7E8R
  11771. Description:
  11772. DmWapPushService: Failed to register WNF with EventAggregator for WAP messages received by SMS Router. Result: (0xC0020036).
  11773. Event Xml:
  11774. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11775. <System>
  11776. <Provider Name="Microsoft-Windows-DeviceManagement-Pushrouter" Guid="{F1201B5A-E170-42B6-8D20-B57AC57E6416}" />
  11777. <EventID>506</EventID>
  11778. <Version>0</Version>
  11779. <Level>2</Level>
  11780. <Task>0</Task>
  11781. <Opcode>0</Opcode>
  11782. <Keywords>0x8000000000000000</Keywords>
  11783. <TimeCreated SystemTime="2016-08-23T23:11:23.031162900Z" />
  11784. <EventRecordID>6</EventRecordID>
  11785. <Correlation />
  11786. <Execution ProcessID="96" ThreadID="8" />
  11787. <Channel>Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin</Channel>
  11788. <Computer>WIN-KUKHEJE7E8R</Computer>
  11789. <Security UserID="S-1-5-18" />
  11790. </System>
  11791. <EventData>
  11792. <Data Name="HexInt1">0xc0020036</Data>
  11793. </EventData>
  11794. </Event>
  11795.  
  11796. Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
  11797. Source: Microsoft-Windows-Kernel-EventTracing
  11798. Date: 8/23/2016 4:11:13 PM
  11799. Event ID: 3
  11800. Task Category: Session
  11801. Level: Error
  11802. Keywords: Session
  11803. User: SYSTEM
  11804. Computer: WIN-KUKHEJE7E8R
  11805. Description:
  11806. Session "AutoLogger-Diagtrack-Listener" stopped due to the following error: 0xC000003A
  11807. Event Xml:
  11808. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  11809. <System>
  11810. <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
  11811. <EventID>3</EventID>
  11812. <Version>1</Version>
  11813. <Level>2</Level>
  11814. <Task>2</Task>
  11815. <Opcode>14</Opcode>
  11816. <Keywords>0x8000000000000010</Keywords>
  11817. <TimeCreated SystemTime="2016-08-23T23:11:13.876743200Z" />
  11818. <EventRecordID>1</EventRecordID>
  11819. <Correlation />
  11820. <Execution ProcessID="4" ThreadID="144" />
  11821. <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
  11822. <Computer>WIN-KUKHEJE7E8R</Computer>
  11823. <Security UserID="S-1-5-18" />
  11824. </System>
  11825. <EventData>
  11826. <Data Name="SessionName">AutoLogger-Diagtrack-Listener</Data>
  11827. <Data Name="FileName">x:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl</Data>
  11828. <Data Name="ErrorCode">3221225530</Data>
  11829. <Data Name="LoggingMode">142606337</Data>
  11830. <Data Name="FailureReason">0</Data>
  11831. </EventData>
  11832. </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement