Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- //Kernel Power Error
- Log Name: System
- Source: Microsoft-Windows-Kernel-Power
- Date: 8/25/2015 6:02:22 AM
- Event ID: 41
- Task Category: (63)
- Level: Critical
- Keywords: (35184372088832),(2)
- User: SYSTEM
- Computer: Vlad
- Description:
- The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
- <EventID>41</EventID>
- <Version>3</Version>
- <Level>1</Level>
- <Task>63</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000200000000002</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:22.104866800Z" />
- <EventRecordID>7850</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="BugcheckCode">0</Data>
- <Data Name="BugcheckParameter1">0x0</Data>
- <Data Name="BugcheckParameter2">0x0</Data>
- <Data Name="BugcheckParameter3">0x0</Data>
- <Data Name="BugcheckParameter4">0x0</Data>
- <Data Name="SleepInProgress">4</Data>
- <Data Name="PowerButtonTimestamp">0</Data>
- <Data Name="BootAppStatus">0</Data>
- </EventData>
- </Event>
- //
- //FilterManager notification 2 (right before crash/restart)
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 8/25/2015 6:02:21 AM
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords: (70368744177664)
- User: SYSTEM
- Computer: Vlad
- Description:
- File System Filter 'npsvctrig' (10.0, 2015-07-09T23:14:31.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000000</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:21.940794400Z" />
- <EventRecordID>7849</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">10</Data>
- <Data Name="DeviceVersionMinor">0</Data>
- <Data Name="DeviceNameLength">9</Data>
- <Data Name="DeviceName">npsvctrig</Data>
- <Data Name="DeviceTime">2015-07-09T23:14:31.000000000Z</Data>
- <Data Name="ExtraInfoLength">183</Data>
- <Data Name="ExtraInfoString">{ "flags" : "0x00000008" , "registration_version" : "0x00000203" , "tx" : false , "sections" : false , "frame" : 0 , "class_name" : "(null)" , "instances" : [["46000","0x00000000"]] }</Data>
- <Data Name="FilterID">{02000000-0006-0000-53AA-7C221DDFD001}</Data>
- </EventData>
- </Event>
- //
- //FilterManager notification 1 (right before crash/restart)
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 8/25/2015 6:02:21 AM
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords: (70368744177664)
- User: SYSTEM
- Computer: Vlad
- Description:
- File System Filter 'FileCrypt' (10.0, 2015-07-09T23:14:31.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000000</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:21.440825300Z" />
- <EventRecordID>7848</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">10</Data>
- <Data Name="DeviceVersionMinor">0</Data>
- <Data Name="DeviceNameLength">9</Data>
- <Data Name="DeviceName">FileCrypt</Data>
- <Data Name="DeviceTime">2015-07-09T23:14:31.000000000Z</Data>
- <Data Name="ExtraInfoLength">197</Data>
- <Data Name="ExtraInfoString">{ "flags" : "0x00000000" , "registration_version" : "0x00000203" , "tx" : false , "sections" : false , "frame" : 0 , "class_name" : "FSFilter Encryption" , "instances" : [["141100","0x00000000"]] }</Data>
- <Data Name="FilterID">{02000000-0005-0000-3D25-2F221DDFD001}</Data>
- </EventData>
- </Event>
- //
- //Ntfs notification (5 seconds before crash/restart)
- Log Name: System
- Source: Microsoft-Windows-Ntfs
- Date: 8/25/2015 6:02:17 AM
- Event ID: 98
- Task Category: None
- Level: Information
- Keywords: (2)
- User: SYSTEM
- Computer: Vlad
- Description:
- Volume C: (\Device\HarddiskVolume5) is healthy. No action is needed.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Ntfs" Guid="{3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482}" />
- <EventID>98</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000002</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:17.200160200Z" />
- <EventRecordID>7847</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="224" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="DriveName">C:</Data>
- <Data Name="DeviceName">\Device\HarddiskVolume5</Data>
- <Data Name="CorruptionActionState">0</Data>
- </EventData>
- </Event>
- //
- //FilterManager notification (18 seconds before restart)
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 8/25/2015 6:02:04 AM
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords: (70368744177664)
- User: SYSTEM
- Computer: Vlad
- Description:
- File System Filter 'WdFilter' (10.0, 2015-07-09T23:19:05.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000000</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:04.751771100Z" />
- <EventRecordID>7846</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">10</Data>
- <Data Name="DeviceVersionMinor">0</Data>
- <Data Name="DeviceNameLength">8</Data>
- <Data Name="DeviceName">WdFilter</Data>
- <Data Name="DeviceTime">2015-07-09T23:19:05.000000000Z</Data>
- <Data Name="ExtraInfoLength">196</Data>
- <Data Name="ExtraInfoString">{ "flags" : "0x00000010" , "registration_version" : "0x00000203" , "tx" : true , "sections" : false , "frame" : 0 , "class_name" : "FSFilter Anti-Virus" , "instances" : [["328010","0x00000000"]] }</Data>
- <Data Name="FilterID">{02000000-0003-0000-9ECD-3C181DDFD001}</Data>
- </EventData>
- </Event>
- //FilterManager notification (another one, 18 seconds before restart)
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 8/25/2015 6:02:04 AM
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords: (70368744177664)
- User: SYSTEM
- Computer: Vlad
- Description:
- File System Filter 'Wof' (10.0, 2015-08-05T22:13:43.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000000</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:04.750988400Z" />
- <EventRecordID>7845</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">10</Data>
- <Data Name="DeviceVersionMinor">0</Data>
- <Data Name="DeviceNameLength">3</Data>
- <Data Name="DeviceName">Wof</Data>
- <Data Name="DeviceTime">2015-08-05T22:13:43.000000000Z</Data>
- <Data Name="ExtraInfoLength">196</Data>
- <Data Name="ExtraInfoString">{ "flags" : "0x00000010" , "registration_version" : "0x00000203" , "tx" : true , "sections" : false , "frame" : 0 , "class_name" : "FSFilter Compression" , "instances" : [["40700","0x00000000"]] }</Data>
- <Data Name="FilterID">{02000000-0002-0000-9ECD-3C181DDFD001}</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 8/25/2015 6:02:04 AM
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords: (70368744177664)
- User: SYSTEM
- Computer: Vlad
- Description:
- File System Filter 'FileInfo' (10.0, 2015-07-09T23:14:57.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>1</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000400000000000</Keywords>
- <TimeCreated SystemTime="2015-08-25T10:02:04.750373900Z" />
- <EventRecordID>7844</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Vlad</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">10</Data>
- <Data Name="DeviceVersionMinor">0</Data>
- <Data Name="DeviceNameLength">8</Data>
- <Data Name="DeviceName">FileInfo</Data>
- <Data Name="DeviceTime">2015-07-09T23:14:57.000000000Z</Data>
- <Data Name="ExtraInfoLength">192</Data>
- <Data Name="ExtraInfoString">{ "flags" : "0x00000010" , "registration_version" : "0x00000203" , "tx" : false , "sections" : false , "frame" : 0 , "class_name" : "FSFilter Bottom" , "instances" : [["45000","0x00000000"]] }</Data>
- <Data Name="FilterID">{02000000-0001-0000-9ECD-3C181DDFD001}</Data>
- </EventData>
- </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement