Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Log Name: System
- Source: Microsoft-Windows-Power-Troubleshooter
- Date: 5/28/2016 3:29:40 AM
- Event ID: 1
- Task Category: None
- Level: Information
- Keywords:
- User: LOCAL SERVICE
- Computer: Eric-Desktop
- Description:
- The system has returned from a low power state.
- Sleep Time: 2016-05-28T04:27:23.250520800Z
- Wake Time: 2016-05-28T08:29:32.029485100Z
- Wake Source: Unknown
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Power-Troubleshooter" Guid="{CDC05E28-C449-49C6-B9D2-88CF761644DF}" />
- <EventID>1</EventID>
- <Version>2</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2016-05-28T08:29:40.244918800Z" />
- <EventRecordID>891</EventRecordID>
- <Correlation ActivityID="{CE1ECDF6-8CB1-425B-A30A-C2CBDC05D740}" />
- <Execution ProcessID="1352" ThreadID="6512" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security UserID="S-1-5-19" />
- </System>
- <EventData>
- <Data Name="SleepTime">2016-05-28T04:27:23.250520800Z</Data>
- <Data Name="WakeTime">2016-05-28T08:29:32.029485100Z</Data>
- <Data Name="SleepDuration">745</Data>
- <Data Name="WakeDuration">533</Data>
- <Data Name="DriverInitDuration">480</Data>
- <Data Name="BiosInitDuration">1613</Data>
- <Data Name="HiberWriteDuration">2378</Data>
- <Data Name="HiberReadDuration">0</Data>
- <Data Name="HiberPagesWritten">250560</Data>
- <Data Name="Attributes">16641</Data>
- <Data Name="TargetState">4</Data>
- <Data Name="EffectiveState">5</Data>
- <Data Name="WakeSourceType">0</Data>
- <Data Name="WakeSourceTextLength">0</Data>
- <Data Name="WakeSourceText">
- </Data>
- <Data Name="WakeTimerOwnerLength">0</Data>
- <Data Name="WakeTimerContextLength">0</Data>
- <Data Name="NoMultiStageResumeReason">0</Data>
- <Data Name="WakeTimerOwner">
- </Data>
- <Data Name="WakeTimerContext">
- </Data>
- </EventData>
- </Event>
- Log Name: System
- Source: e1dexpress
- Date: 5/28/2016 3:29:35 AM
- Event ID: 32
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Eric-Desktop
- Description:
- Intel(R) Ethernet Connection (2) I219-V
- Network link has been established at 1Gbps full duplex.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="e1dexpress" />
- <EventID Qualifiers="24580">32</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2016-05-28T08:29:35.111437900Z" />
- <EventRecordID>890</EventRecordID>
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security />
- </System>
- <EventData>
- <Data>
- </Data>
- <Data>Intel(R) Ethernet Connection (2) I219-V</Data>
- <Binary>0000040002003000000000002000046000000000000000000000000000000000000000000000000020000460</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-Power
- Date: 5/28/2016 3:29:32 AM
- Event ID: 131
- Task Category: (33)
- Level: Information
- Keywords: (4)
- User: N/A
- Computer: Eric-Desktop
- Description:
- Firmware S3 times. ResumeCount: 1, FullResume: 1574, AverageResume: 1574
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
- <EventID>131</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>33</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000004</Keywords>
- <TimeCreated SystemTime="2016-05-28T08:29:32.000768800Z" />
- <EventRecordID>889</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="3408" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="ResumeCount">1</Data>
- <Data Name="FullResume">1574</Data>
- <Data Name="AverageResume">1574</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 5/28/2016 3:29:31 AM
- Event ID: 1
- Task Category: None
- Level: Information
- Keywords: Time
- User: N/A
- Computer: Eric-Desktop
- Description:
- The system time has changed to 2016-05-28T08:29:31.500000000Z from 2016-05-28T04:27:25.256022200Z.
- Change Reason: System time synchronized with the hardware clock.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>1</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000010</Keywords>
- <TimeCreated SystemTime="2016-05-28T08:29:31.499948300Z" />
- <EventRecordID>888</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="3408" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="NewTime">2016-05-28T08:29:31.500000000Z</Data>
- <Data Name="OldTime">2016-05-28T04:27:25.256022200Z</Data>
- <Data Name="Reason">2</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-Power
- Date: 5/27/2016 11:27:25 PM
- Event ID: 107
- Task Category: (102)
- Level: Information
- Keywords: (70368744177664),(64),(4)
- User: N/A
- Computer: Eric-Desktop
- Description:
- The system has resumed from sleep.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
- <EventID>107</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>102</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000044</Keywords>
- <TimeCreated SystemTime="2016-05-28T04:27:25.255914100Z" />
- <EventRecordID>887</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="3408" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="TargetState">4</Data>
- <Data Name="EffectiveState">5</Data>
- <Data Name="WakeFromState">4</Data>
- <Data Name="ProgrammedWakeTimeAc">1601-01-01T00:00:00.000000000Z</Data>
- <Data Name="ProgrammedWakeTimeDc">2016-05-28T03:29:30.000000100Z</Data>
- <Data Name="WakeRequesterTypeAc">0</Data>
- <Data Name="WakeRequesterTypeDc">2</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-Power
- Date: 5/27/2016 11:27:23 PM
- Event ID: 42
- Task Category: (64)
- Level: Information
- Keywords: (70368744177664),(4)
- User: N/A
- Computer: Eric-Desktop
- Description:
- The system is entering sleep.
- Sleep Reason: Application API
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
- <EventID>42</EventID>
- <Version>2</Version>
- <Level>4</Level>
- <Task>64</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000004</Keywords>
- <TimeCreated SystemTime="2016-05-28T04:27:23.845309900Z" />
- <EventRecordID>886</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="3408" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="TargetState">4</Data>
- <Data Name="EffectiveState">5</Data>
- <Data Name="Reason">4</Data>
- <Data Name="Flags">0</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-DistributedCOM
- Date: 5/27/2016 11:27:23 PM
- Event ID: 10016
- Task Category: None
- Level: Error
- Keywords: Classic
- User: SYSTEM
- Computer: Eric-Desktop
- Description:
- The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
- <EventID Qualifiers="0">10016</EventID>
- <Version>0</Version>
- <Level>2</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2016-05-28T04:27:23.584795100Z" />
- <EventRecordID>885</EventRecordID>
- <Correlation />
- <Execution ProcessID="916" ThreadID="6096" />
- <Channel>System</Channel>
- <Computer>Eric-Desktop</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="param1">application-specific</Data>
- <Data Name="param2">Local</Data>
- <Data Name="param3">Activation</Data>
- <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
- <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
- <Data Name="param6">NT AUTHORITY</Data>
- <Data Name="param7">SYSTEM</Data>
- <Data Name="param8">S-1-5-18</Data>
- <Data Name="param9">LocalHost (Using LRPC)</Data>
- <Data Name="param10">Unavailable</Data>
- <Data Name="param11">Unavailable</Data>
- </EventData>
- </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement