Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Log Name: System
- Source: Microsoft-Windows-Kernel-Power
- Date: 10/02/2017 01:04:24 p.m.
- Event ID: 41
- Task Category: (63)
- Level: Critical
- Keywords: (2)
- User: SYSTEM
- Computer: Ermitaño-PC
- Description:
- The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
- <EventID>41</EventID>
- <Version>2</Version>
- <Level>1</Level>
- <Task>63</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000002</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:24.053609700Z" />
- <EventRecordID>734</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="BugcheckCode">0</Data>
- <Data Name="BugcheckParameter1">0x0</Data>
- <Data Name="BugcheckParameter2">0x0</Data>
- <Data Name="BugcheckParameter3">0x0</Data>
- <Data Name="BugcheckParameter4">0x0</Data>
- <Data Name="SleepInProgress">false</Data>
- <Data Name="PowerButtonTimestamp">131312269550458897</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/02/2017 01:04:31 p.m.
- Event ID: 6013
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The system uptime is 14 seconds.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6013</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:31.000000000Z" />
- <EventRecordID>733</EventRecordID>
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>14</Data>
- <Data>60</Data>
- <Data>360 Central Standard Time (Mexico)</Data>
- <Binary>31002E003100000030000000570069006E0064006F007700730020003700200055006C00740069006D00610074006500000036002E0031002E00370036003000310020004200750069006C006400200037003600300031002000530065007200760069006300650020005000610063006B002000310000004D0075006C0074006900700072006F0063006500730073006F00720020004600720065006500000037003600300031002E00770069006E0037007300700031005F00720074006D002E003100300031003100310039002D00310038003500300000003500380039006400370066006100380000004E006F007400200041007600610069006C00610062006C00650000004E006F007400200041007600610069006C00610062006C006500000039000000380000003100360032003800350000003800300061000000450072006D00690074006100F1006F002D005000430000000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/02/2017 01:04:31 p.m.
- Event ID: 6005
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Event log service was started.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6005</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:31.000000000Z" />
- <EventRecordID>732</EventRecordID>
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Binary>E107020005000A00130004001F0046030000000000000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/02/2017 01:04:31 p.m.
- Event ID: 6009
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6009</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:31.000000000Z" />
- <EventRecordID>731</EventRecordID>
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data>6.01.</Data>
- <Data>7601</Data>
- <Data>Service Pack 1</Data>
- <Data>Multiprocessor Free</Data>
- <Data>17514</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/02/2017 01:04:31 p.m.
- Event ID: 6008
- Task Category: None
- Level: Error
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The previous system shutdown at 01:02:21 p.m. on 10/02/2017 was unexpected.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6008</EventID>
- <Level>2</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:31.000000000Z" />
- <EventRecordID>730</EventRecordID>
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data>01:02:21 p.m.</Data>
- <Data>10/02/2017</Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>35645</Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Binary>E107020005000A000D00020015008F01E107020005000A001300020015008F01600900003C000000010000006009000000000000B00400000100000000000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-FilterManager
- Date: 10/02/2017 01:04:21 p.m.
- Event ID: 6
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Ermitaño-PC
- Description:
- File System Filter 'FileInfo' (6.1, 2009-07-13T17:34:25.000000000Z) has successfully loaded and registered with Filter Manager.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-FilterManager" Guid="{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}" />
- <EventID>6</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:21.713605600Z" />
- <EventRecordID>729</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="FinalStatus">0x0</Data>
- <Data Name="DeviceVersionMajor">6</Data>
- <Data Name="DeviceVersionMinor">1</Data>
- <Data Name="DeviceNameLength">8</Data>
- <Data Name="DeviceName">FileInfo</Data>
- <Data Name="DeviceTime">2009-07-13T17:34:25.000000000Z</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: Microsoft-Windows-Kernel-General
- Date: 10/02/2017 01:04:18 p.m.
- Event ID: 12
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: Ermitaño-PC
- Description:
- The operating system started at system time 2017-02-10T19:04:17.595198400Z.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
- <EventID>12</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T19:04:18.827600600Z" />
- <EventRecordID>728</EventRecordID>
- <Correlation />
- <Execution ProcessID="4" ThreadID="8" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- <Data Name="MajorVersion">6</Data>
- <Data Name="MinorVersion">1</Data>
- <Data Name="BuildVersion">7601</Data>
- <Data Name="QfeVersion">17514</Data>
- <Data Name="ServiceVersion">1</Data>
- <Data Name="BootMode">0</Data>
- <Data Name="StartTime">2017-02-10T19:04:17.595198400Z</Data>
- </EventData>
- </Event>
- Log Name: System
- Source: EventLog
- Date: 10/02/2017 12:00:21 p.m.
- Event ID: 6013
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The system uptime is 31925 seconds.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="EventLog" />
- <EventID Qualifiers="32768">6013</EventID>
- <Level>4</Level>
- <Task>0</Task>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T18:00:21.000000000Z" />
- <EventRecordID>727</EventRecordID>
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>
- </Data>
- <Data>31925</Data>
- <Data>60</Data>
- <Data>360 Central Standard Time (Mexico)</Data>
- <Binary>31002E003100000030000000570069006E0064006F007700730020003700200055006C00740069006D00610074006500000036002E0031002E00370036003000310020004200750069006C006400200037003600300031002000530065007200760069006300650020005000610063006B002000310000004D0075006C0074006900700072006F0063006500730073006F00720020004600720065006500000037003600300031002E00770069006E0037007300700031005F00720074006D002E003100300031003100310039002D00310038003500300000003500380039006400370066006100380000004E006F007400200041007600610069006C00610062006C00650000004E006F007400200041007600610069006C00610062006C006500000039000000380000003100360032003800350000003800300061000000450072006D00690074006100F1006F002D005000430000000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 08:22:22 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The WinHTTP Web Proxy Auto-Discovery Service service entered the stopped state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T14:22:22.535269100Z" />
- <EventRecordID>726</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="6000" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">WinHTTP Web Proxy Auto-Discovery Service</Data>
- <Data Name="param2">stopped</Data>
- <Binary>570069006E0048007400740070004100750074006F00500072006F00780079005300760063002F0031000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 08:05:55 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Google Update Servicio (gupdate) service entered the stopped state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T14:05:55.550816800Z" />
- <EventRecordID>725</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="4868" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Google Update Servicio (gupdate)</Data>
- <Data Name="param2">stopped</Data>
- <Binary>67007500700064006100740065002F0031000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 08:05:52 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The WinHTTP Web Proxy Auto-Discovery Service service entered the running state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T14:05:52.534644300Z" />
- <EventRecordID>724</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="4868" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">WinHTTP Web Proxy Auto-Discovery Service</Data>
- <Data Name="param2">running</Data>
- <Binary>570069006E0048007400740070004100750074006F00500072006F00780079005300760063002F0034000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 08:05:52 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Google Update Servicio (gupdate) service entered the running state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T14:05:52.286630100Z" />
- <EventRecordID>723</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="4868" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Google Update Servicio (gupdate)</Data>
- <Data Name="param2">running</Data>
- <Binary>67007500700064006100740065002F0034000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 05:07:44 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Application Experience service entered the stopped state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T11:07:44.926348100Z" />
- <EventRecordID>722</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="2464" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Application Experience</Data>
- <Data Name="param2">stopped</Data>
- <Binary>410065004C006F006F006B00750070005300760063002F0031000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 04:57:41 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Application Experience service entered the running state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T10:57:41.987862000Z" />
- <EventRecordID>721</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="5968" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Application Experience</Data>
- <Data Name="param2">running</Data>
- <Binary>410065004C006F006F006B00750070005300760063002F0034000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 04:40:37 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Application Experience service entered the stopped state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T10:40:37.686275300Z" />
- <EventRecordID>720</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="5816" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Application Experience</Data>
- <Data Name="param2">stopped</Data>
- <Binary>410065004C006F006F006B00750070005300760063002F0031000000</Binary>
- </EventData>
- </Event>
- Log Name: System
- Source: Service Control Manager
- Date: 10/02/2017 04:30:47 a.m.
- Event ID: 7036
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: Ermitaño-PC
- Description:
- The Portable Device Enumerator Service service entered the stopped state.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
- <EventID Qualifiers="16384">7036</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8080000000000000</Keywords>
- <TimeCreated SystemTime="2017-02-10T10:30:47.995546900Z" />
- <EventRecordID>719</EventRecordID>
- <Correlation />
- <Execution ProcessID="588" ThreadID="3008" />
- <Channel>System</Channel>
- <Computer>Ermitaño-PC</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="param1">Portable Device Enumerator Service</Data>
- <Data Name="param2">stopped</Data>
- <Binary>57005000440042007500730045006E0075006D002F0031000000</Binary>
- </EventData>
- </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement