Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Level Date and Time Source Event ID Task Category
- Warning 2/24/2018 6:35:35 AM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Error 2/23/2018 10:25:49 PM Service Control Manager 7031 None The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
- Error 2/23/2018 10:25:47 PM Application Error 1000 (100) "Faulting application name: svchost.exe_SysMain, version: 10.0.16299.15, time stamp: 0x9c786b9a
- Faulting module name: sysmain.dll, version: 10.0.16299.192, time stamp: 0x18305a23
- Exception code: 0xc0000005
- Fault offset: 0x000000000003314d
- Faulting process id: 0x694
- Faulting application start time: 0x01d3ad20827d6701
- Faulting application path: C:\WINDOWS\system32\svchost.exe
- Faulting module path: c:\windows\system32\sysmain.dll
- Report Id: f0ba3ed0-5557-4495-97a1-487b65672c55
- Faulting package full name:
- Faulting package-relative application ID: "
- Error 2/23/2018 8:38:20 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user DESKTOP-Q0RA225\Porters SID (S-1-5-21-593368070-1873816976-3573321391-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Warning 2/23/2018 8:36:33 PM Microsoft-Windows-User Device Registration 360 None "Windows Hello for Business provisioning will not be launched.
- Device is AAD joined ( AADJ or DJ++ ): Not Tested
- User has logged on with AAD credentials: No
- Windows Hello for Business policy is enabled: Not Tested
- Local computer meets Windows hello for business hardware requirements: Not Tested
- User is not connected to the machine via Remote Desktop: Yes
- User certificate for on premise auth policy is enabled: Not Tested
- Machine is governed by none policy.
- See https://go.microsoft.com/fwlink/?linkid=832647 for more details."
- Error 2/23/2018 8:36:31 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 8:36:31 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 8:36:31 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 8:36:31 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 8:35:41 PM Microsoft-Windows-WER-SystemErrorReporting 1001 None The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xffffffffffffffff, 0x000000000000000a, 0x0000000000000008, 0xffffffffffffffff). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 38c4cf8e-eafb-4f5d-85cc-07155e30d19b.
- Error 2/23/2018 8:35:26 PM Microsoft-Windows-Eventlog 1101 Event processing Audit events have been dropped by the transport. 0
- Critical 2/23/2018 8:35:08 PM Microsoft-Windows-Kernel-Power 41 (63) The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
- Error 2/23/2018 8:35:26 PM EventLog 6008 None The previous system shutdown at 8:33:01 PM on β2/β23/β2018 was unexpected.
- Error 2/23/2018 5:56:23 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {D63B10C5-BB46-4990-A94F-E40B9D520160}
- and APPID
- {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
- to the user DESKTOP-Q0RA225\Porters SID (S-1-5-21-593368070-1873816976-3573321391-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:53:23 PM Microsoft-Windows-DistributedCOM 10016 None "The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {C2F03A33-21F5-47FA-B4BB-156362A2F239}
- and APPID
- {316CDED5-E4AE-4B15-9113-7055D84DCC97}
- to the user DESKTOP-Q0RA225\Porters SID (S-1-5-21-593368070-1873816976-3573321391-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.9.6.16299_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:53:23 PM Microsoft-Windows-DistributedCOM 10016 None "The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {C2F03A33-21F5-47FA-B4BB-156362A2F239}
- and APPID
- {316CDED5-E4AE-4B15-9113-7055D84DCC97}
- to the user DESKTOP-Q0RA225\Porters SID (S-1-5-21-593368070-1873816976-3573321391-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.9.6.16299_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool."
- Warning 2/23/2018 5:53:15 PM Microsoft-Windows-User Device Registration 360 None "Windows Hello for Business provisioning will not be launched.
- Device is AAD joined ( AADJ or DJ++ ): Not Tested
- User has logged on with AAD credentials: No
- Windows Hello for Business policy is enabled: Not Tested
- Local computer meets Windows hello for business hardware requirements: Not Tested
- User is not connected to the machine via Remote Desktop: Yes
- User certificate for on premise auth policy is enabled: Not Tested
- Machine is governed by none policy.
- See https://go.microsoft.com/fwlink/?linkid=832647 for more details."
- Error 2/23/2018 5:53:15 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:53:15 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:53:15 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:53:15 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Warning 2/23/2018 5:51:43 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Warning 2/23/2018 5:51:43 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Warning 2/23/2018 5:51:42 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Warning 2/23/2018 5:51:42 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Error 2/23/2018 5:50:49 PM VSS 8193 None "Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
- .
- Operation:
- Executing Asynchronous Operation
- Context:
- Current State: DoSnapshotSet"
- Warning 2/23/2018 5:43:26 PM Microsoft-Windows-User Device Registration 360 None "Windows Hello for Business provisioning will not be launched.
- Device is AAD joined ( AADJ or DJ++ ): Not Tested
- User has logged on with AAD credentials: No
- Windows Hello for Business policy is enabled: Not Tested
- Local computer meets Windows hello for business hardware requirements: Not Tested
- User is not connected to the machine via Remote Desktop: Yes
- User certificate for on premise auth policy is enabled: Not Tested
- Machine is governed by none policy.
- See https://go.microsoft.com/fwlink/?linkid=832647 for more details."
- Error 2/23/2018 5:43:25 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:43:25 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:43:25 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Error 2/23/2018 5:43:25 PM Microsoft-Windows-DistributedCOM 10016 None "The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
- {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
- and APPID
- {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
- to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
- Warning 2/23/2018 5:42:51 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Warning 2/23/2018 5:42:51 PM Microsoft-Windows-DeviceSetupManager 122 None Access to drivers on Windows Update was blocked by policy
- Error 2/23/2018 5:40:21 PM VSS 8193 None "Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
- .
- Operation:
- Executing Asynchronous Operation
- Context:
- Current State: DoSnapshotSet"
- Warning 2/23/2018 5:40:14 PM Microsoft-Windows-Kernel-PnP 225 (223) The application \Device\HarddiskVolume2\Windows\System32\audiodg.exe with process id 8216 stopped the removal or ejection for the device HDAUDIO\FUNC_01&VEN_10EC&DEV_0892&SUBSYS_10438698&REV_1003\4&1a86e4fd&0&0001.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement