Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:54
- Event ID: 8233
- Task Category: None
- Level: Warning
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The rules engine reported a failed VL activation attempt.
- Reason:0x8007232B
- AppId = 0ff1ce15-a989-479d-af46-f275c6370663, SkuId = d450596f-894d-49e0-966a-fd39ed4c4c64
- Trigger=UserLogon(1)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">8233</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:54.6474859Z" />
- <EventRecordID>1129</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>0x8007232B</Data>
- <Data>0ff1ce15-a989-479d-af46-f275c6370663</Data>
- <Data>d450596f-894d-49e0-966a-fd39ed4c4c64</Data>
- <Data>UserLogon(1)</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Search
- Date: 24/04/2021 16:05:52
- Event ID: 1003
- Task Category: Search service
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The Windows Search Service started.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
- <EventID Qualifiers="16384">1003</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:52.0624817Z" />
- <EventRecordID>1128</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data Name="ExtraInfo">
- </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 326
- Task Category: (1)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,D,50) Windows: The database engine attached a database (1, C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb). (Time=0 seconds)
- Saved Cache: 0 0
- Additional Data: lgposAttach = 00000066:0094:0268,
- dbv = 1568.110.240
- Internal Timing Sequence:
- [1] 0.000002 +J(0)
- [2] 0.000286 +J(0) +M(C:0K, Fs:24, WS:32K # 0K, PF:32K # 0K, P:32K)
- [3] 0.005070 -0.001623 (5) WT +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:3480/2) +M(C:0K, Fs:17, WS:36K # 0K, PF:40K # 0K, P:40K)
- [4] 0.000077 +J(0)
- [5] -
- [6] -
- [7] -
- [8] 0.001950 -0.000847 (2) CM +J(CM:2, PgRf:2, Rd:14/2, Dy:0/0, Lg:54/1) +M(C:0K, Fs:23, WS:92K # 0K, PF:608K # 0K, P:608K)
- [9] 0.007057 -0.000166 (5) CM -0.006671 (1) WT +J(CM:5, PgRf:23, Rd:0/5, Dy:0/0, Lg:0/0) +M(C:0K, Fs:55, WS:220K # 0K, PF:224K # 0K, P:224K)
- [10] 0.000293 -0.000218 (1) CM +J(CM:1, PgRf:40, Rd:0/1, Dy:0/0, Lg:0/0) +M(C:0K, Fs:9, WS:36K # 0K, PF:32K # 0K, P:32K)
- [11] 0.000007 +J(CM:0, PgRf:1, Rd:0/0, Dy:0/0, Lg:0/0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
- [12] 0.000022 +J(CM:0, PgRf:42, Rd:0/0, Dy:0/0, Lg:0/0) +M(C:0K, Fs:3, WS:12K # 0K, PF:0K # 0K, P:0K)
- [13] 0.0 +J(0)
- [14] 0.0 +J(0)
- [15] 0.000003 +J(CM:0, PgRf:1, Rd:0/0, Dy:0/0, Lg:0/0).
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">326</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.9622430Z" />
- <EventRecordID>1127</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,D,50</Data>
- <Data>Windows: </Data>
- <Data>1</Data>
- <Data>C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb</Data>
- <Data>0</Data>
- <Data>
- [1] 0.000002 +J(0)
- [2] 0.000286 +J(0) +M(C:0K, Fs:24, WS:32K # 0K, PF:32K # 0K, P:32K)
- [3] 0.005070 -0.001623 (5) WT +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:3480/2) +M(C:0K, Fs:17, WS:36K # 0K, PF:40K # 0K, P:40K)
- [4] 0.000077 +J(0)
- [5] -
- [6] -
- [7] -
- [8] 0.001950 -0.000847 (2) CM +J(CM:2, PgRf:2, Rd:14/2, Dy:0/0, Lg:54/1) +M(C:0K, Fs:23, WS:92K # 0K, PF:608K # 0K, P:608K)
- [9] 0.007057 -0.000166 (5) CM -0.006671 (1) WT +J(CM:5, PgRf:23, Rd:0/5, Dy:0/0, Lg:0/0) +M(C:0K, Fs:55, WS:220K # 0K, PF:224K # 0K, P:224K)
- [10] 0.000293 -0.000218 (1) CM +J(CM:1, PgRf:40, Rd:0/1, Dy:0/0, Lg:0/0) +M(C:0K, Fs:9, WS:36K # 0K, PF:32K # 0K, P:32K)
- [11] 0.000007 +J(CM:0, PgRf:1, Rd:0/0, Dy:0/0, Lg:0/0) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
- [12] 0.000022 +J(CM:0, PgRf:42, Rd:0/0, Dy:0/0, Lg:0/0) +M(C:0K, Fs:3, WS:12K # 0K, PF:0K # 0K, P:0K)
- [13] 0.0 +J(0)
- [14] 0.0 +J(0)
- [15] 0.000003 +J(CM:0, PgRf:1, Rd:0/0, Dy:0/0, Lg:0/0).</Data>
- <Data>0 0</Data>
- <Data>lgposAttach = 00000066:0094:0268,
- dbv = 1568.110.240</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:51
- Event ID: 8233
- Task Category: None
- Level: Warning
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The rules engine reported a failed VL activation attempt.
- Reason:0x8007232B
- AppId = 0ff1ce15-a989-479d-af46-f275c6370663, SkuId = d450596f-894d-49e0-966a-fd39ed4c4c64
- Trigger=NetworkAvailable
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">8233</EventID>
- <Version>0</Version>
- <Level>3</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.9466219Z" />
- <EventRecordID>1126</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>0x8007232B</Data>
- <Data>0ff1ce15-a989-479d-af46-f275c6370663</Data>
- <Data>d450596f-894d-49e0-966a-fd39ed4c4c64</Data>
- <Data>NetworkAvailable</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 105
- Task Category: (1)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,D,0) Windows: The database engine started a new instance (0). (Time=0 seconds)
- Additional Data:
- lgposV2[] = 00000065:009D:0000 - 00000065:00FD:0609 - 00000066:0092:0000 - 00000066:0092:0000 (00000000:0000:0000)
- cReInits = 1
- Internal Timing Sequence:
- [1] 0.000612 +J(0) +M(C:0K, Fs:191, WS:732K # 732K, PF:5392K # 5392K, P:5392K)
- [2] 0.000259 +J(0) +M(C:0K, Fs:227, WS:908K # 908K, PF:448K # 448K, P:448K)
- [3] 0.000027 +J(0) +M(C:0K, Fs:27, WS:104K # 104K, PF:68K # 68K, P:68K)
- [4] 0.000099 +J(0) +M(C:0K, Fs:39, WS:152K # 152K, PF:368K # 368K, P:368K)
- [5] 0.001074 +J(0) +M(C:0K, Fs:9, WS:36K # 36K, PF:24K # 32K, P:24K)
- [6] 0.002401 +J(0) +M(C:0K, Fs:23, WS:92K # 92K, PF:12K # 4K, P:12K)
- [7] 0.001714 +J(0) +M(C:0K, Fs:271, WS:1080K # 1080K, PF:1028K # 1028K, P:1028K)
- [8] 0.143796 -0.107082 (511) CM -0.003827 (7) WT +J(CM:511, PgRf:2759, Rd:0/511, Dy:49/719, Lg:390063/10855) +M(C:0K, Fs:4739, WS:11772K # 11772K, PF:11612K # 11612K, P:11612K)
- [9] 0.054358 -0.002756 (403) CM -0.000763 (5) WT +J(CM:403, PgRf:5351, Rd:333/403, Dy:163/6049, Lg:586236/21188) +M(C:0K, Fs:3295, WS:340K # 360K, PF:252K # 252K, P:252K) + 1 lgens
- [10] 0.000655 +J(0) +M(C:0K, Fs:0, WS:-1020K # 0K, PF:-1020K # 0K, P:-1020K)
- [11] 0.000028 +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:49/1) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
- [12] 0.033561 -0.000006 (142) CM -0.029859 (3) WT +J(CM:142, PgRf:0, Rd:0/142, Dy:0/0, Lg:0/0) +M(C:0K, Fs:898, WS:-56K # 0K, PF:-64K # 0K, P:-64K)
- [13] 0.038235 -0.000424 (2) CM -0.029646 (22) WT +J(CM:2, PgRf:2, Rd:0/2, Dy:0/0, Lg:8759/5) +M(C:0K, Fs:309, WS:-10852K # 0K, PF:-10244K # 0K, P:-10244K)
- [14] 0.000017 +J(0)
- [15] 0.000035 +J(0)
- [16] 0.000123 +J(0) +M(C:0K, Fs:2, WS:0K # 0K, PF:0K # 0K, P:0K).
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">105</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.9310001Z" />
- <EventRecordID>1125</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,D,0</Data>
- <Data>Windows: </Data>
- <Data>0</Data>
- <Data>0</Data>
- <Data>
- [1] 0.000612 +J(0) +M(C:0K, Fs:191, WS:732K # 732K, PF:5392K # 5392K, P:5392K)
- [2] 0.000259 +J(0) +M(C:0K, Fs:227, WS:908K # 908K, PF:448K # 448K, P:448K)
- [3] 0.000027 +J(0) +M(C:0K, Fs:27, WS:104K # 104K, PF:68K # 68K, P:68K)
- [4] 0.000099 +J(0) +M(C:0K, Fs:39, WS:152K # 152K, PF:368K # 368K, P:368K)
- [5] 0.001074 +J(0) +M(C:0K, Fs:9, WS:36K # 36K, PF:24K # 32K, P:24K)
- [6] 0.002401 +J(0) +M(C:0K, Fs:23, WS:92K # 92K, PF:12K # 4K, P:12K)
- [7] 0.001714 +J(0) +M(C:0K, Fs:271, WS:1080K # 1080K, PF:1028K # 1028K, P:1028K)
- [8] 0.143796 -0.107082 (511) CM -0.003827 (7) WT +J(CM:511, PgRf:2759, Rd:0/511, Dy:49/719, Lg:390063/10855) +M(C:0K, Fs:4739, WS:11772K # 11772K, PF:11612K # 11612K, P:11612K)
- [9] 0.054358 -0.002756 (403) CM -0.000763 (5) WT +J(CM:403, PgRf:5351, Rd:333/403, Dy:163/6049, Lg:586236/21188) +M(C:0K, Fs:3295, WS:340K # 360K, PF:252K # 252K, P:252K) + 1 lgens
- [10] 0.000655 +J(0) +M(C:0K, Fs:0, WS:-1020K # 0K, PF:-1020K # 0K, P:-1020K)
- [11] 0.000028 +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:49/1) +M(C:0K, Fs:1, WS:4K # 0K, PF:0K # 0K, P:0K)
- [12] 0.033561 -0.000006 (142) CM -0.029859 (3) WT +J(CM:142, PgRf:0, Rd:0/142, Dy:0/0, Lg:0/0) +M(C:0K, Fs:898, WS:-56K # 0K, PF:-64K # 0K, P:-64K)
- [13] 0.038235 -0.000424 (2) CM -0.029646 (22) WT +J(CM:2, PgRf:2, Rd:0/2, Dy:0/0, Lg:8759/5) +M(C:0K, Fs:309, WS:-10852K # 0K, PF:-10244K # 0K, P:-10244K)
- [14] 0.000017 +J(0)
- [15] 0.000035 +J(0)
- [16] 0.000123 +J(0) +M(C:0K, Fs:2, WS:0K # 0K, PF:0K # 0K, P:0K).</Data>
- <Data>lgposV2[] = 00000065:009D:0000 - 00000065:00FD:0609 - 00000066:0092:0000 - 00000066:0092:0000 (00000000:0000:0000)
- cReInits = 1
- </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 302
- Task Category: (3)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,U,98) Windows: The database engine has successfully completed recovery steps.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">302</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>3</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.9310001Z" />
- <EventRecordID>1124</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,U,98</Data>
- <Data>Windows: </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 301
- Task Category: (3)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,R,98) Windows: The database engine has finished replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx.
- Processing Stats:
- [1] 0.049424 -0.002756 (403) CM -0.000763 (5) WT +J(CM:403, PgRf:5351, Rd:324/403, Dy:163/6049, Lg:586236/21188) +M(C:0K, Fs:3266, WS:356K # 316K, PF:236K # 172K, P:236K).
- Log record of type 'Commit ' was seen most frequently (5292 times)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">301</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>3</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.8620024Z" />
- <EventRecordID>1123</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,R,98</Data>
- <Data>Windows: </Data>
- <Data>C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb.jtx</Data>
- <Data>
- [1] 0.049424 -0.002756 (403) CM -0.000763 (5) WT +J(CM:403, PgRf:5351, Rd:324/403, Dy:163/6049, Lg:586236/21188) +M(C:0K, Fs:3266, WS:356K # 316K, PF:236K # 172K, P:236K).</Data>
- <Data>Commit </Data>
- <Data>5292</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 301
- Task Category: (3)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,R,98) Windows: The database engine has finished replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00065.jtx.
- Processing Stats:
- [1] 0.139114 -0.107082 (511) CM -0.003669 (6) WT +J(CM:511, PgRf:2759, Rd:0/511, Dy:49/719, Lg:390063/10855) +M(C:0K, Fs:4473, WS:10716K # 10716K, PF:10792K # 10792K, P:10792K).
- Log record of type 'Commit ' was seen most frequently (2705 times)
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">301</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>3</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.7995166Z" />
- <EventRecordID>1122</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,R,98</Data>
- <Data>Windows: </Data>
- <Data>C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb00065.jtx</Data>
- <Data>
- [1] 0.139114 -0.107082 (511) CM -0.003669 (6) WT +J(CM:511, PgRf:2759, Rd:0/511, Dy:49/719, Lg:390063/10855) +M(C:0K, Fs:4473, WS:10716K # 10716K, PF:10792K # 10792K, P:10792K).</Data>
- <Data>Commit </Data>
- <Data>2705</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 300
- Task Category: (3)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,R,98) Windows: The database engine is initiating recovery steps.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">300</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>3</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.6691480Z" />
- <EventRecordID>1121</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,R,98</Data>
- <Data>Windows: </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: ESENT
- Date: 24/04/2021 16:05:51
- Event ID: 102
- Task Category: (1)
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- SearchIndexer (7676,P,98) Windows: The database engine (10.00.19041.0000) is starting a new instance (0).
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="ESENT" />
- <EventID Qualifiers="0">102</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>1</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:51.6535172Z" />
- <EventRecordID>1120</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SearchIndexer</Data>
- <Data>7676,P,98</Data>
- <Data>Windows: </Data>
- <Data>0</Data>
- <Data>10</Data>
- <Data>00</Data>
- <Data>19041</Data>
- <Data>0000</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Winlogon
- Date: 24/04/2021 16:05:50
- Event ID: 6000
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
- <EventID Qualifiers="32768">6000</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:50.1278394Z" />
- <EventRecordID>1119</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SessionEnv</Data>
- <Binary>D9060000</Binary>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Winlogon
- Date: 24/04/2021 16:05:49
- Event ID: 6003
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
- <EventID Qualifiers="32768">6003</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:49.9651213Z" />
- <EventRecordID>1118</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>SessionEnv</Data>
- <Binary>D9060000</Binary>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-WMI
- Date: 24/04/2021 16:05:48
- Event ID: 5617
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: DESKTOP-T3O9TSS
- Description:
- Windows Management Instrumentation Service subsystems initialized successfully
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
- <EventID>5617</EventID>
- <Version>2</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.2308515Z" />
- <EventRecordID>1117</EventRecordID>
- <Correlation />
- <Execution ProcessID="3472" ThreadID="3848" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:48
- Event ID: 902
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The Software Protection service has started.
- 10.0.19041.867
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">902</EventID>
- <Version>0</Version>
- <Level>0</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.7286948Z" />
- <EventRecordID>1116</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>10.0.19041.867</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:48
- Event ID: 1003
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The Software Protection service has completed licensing status check.
- Application Id=55c92734-d682-4d71-983e-d6ec3f16059f
- Licensing Status=
- 1: 040fa323-92b1-4baf-97a2-5b67feaefddb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 2: 0724cb7d-3437-4cb7-93cb-830375d0079d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 3: 0ad2ac98-7bb9-4201-8d92-312299201369, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 4: 1a9a717a-cf13-4ba5-83c3-0fe25fa868d5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 5: 221a02da-e2a1-4b75-864c-0a4410a33fdf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 6: 291ece0e-9c38-40ca-a9e1-32cc7ec19507, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 7: 2936d1d2-913a-4542-b54e-ce5a602a2a38, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 8: 2c293c26-a45a-4a2a-a350-c69a67097529, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 9: 2de67392-b7a7-462a-b1ca-108dd189f588, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 10: 2ffd8952-423e-4903-b993-72a1aa44cf82, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 11: 30a42c86-b7a0-4a34-8c90-ff177cb2acb7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 12: 345a5db0-d94f-4e3b-a0c0-7c42f7bc3ebf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 13: 3502365a-f88a-4ba4-822a-5769d3073b65, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 14: 377333b1-8b5d-48d6-9679-1225c872d37c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 15: 3df374ef-d444-4494-a5a1-4b0d9fd0e203, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 16: 3f1afc82-f8ac-4f6c-8005-1d233e606eee, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 17: 49cd895b-53b2-4dc4-a5f7-b18aa019ad37, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 18: 4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
- 19: 4f3da0d2-271d-4508-ae81-626b60809a38, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 20: 60b3ec1b-9545-4921-821f-311b129dd6f6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 21: 613d217f-7f13-4268-9907-1662339531cd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 22: 62f0c100-9c53-4e02-b886-a3528ddfe7f6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 23: 6365275e-368d-46ca-a0ef-fc0404119333, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 24: 721f9237-9341-4453-a661-09e8baa6cca5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 25: 73111121-5638-40f6-bc11-f1d7b0d64300, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 26: 7a802526-4c94-4bd1-ba14-835a1aca2120, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 27: 7cb546c0-c7d5-44d8-9a5c-69ecdd782b69, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 28: 82bbc092-bc50-4e16-8e18-b74fc486aec3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 29: 8ab9bdd1-1f67-4997-82d9-8878520837d9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 30: 8b351c9c-f398-4515-9900-09df49427262, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 31: 90da7373-1c51-430b-bf26-c97e9c5cdc31, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 32: 95dca82f-385d-4d39-b85b-5c73fa285d6f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 33: a48938aa-62fa-4966-9d44-9f04da3f72f2, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 34: b0773a15-df3a-4312-9ad2-83d69648e356, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 35: b4bfe195-541e-4e64-ad23-6177f19e395e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 36: b68e61d2-68ca-4757-be45-0cc2f3e68eee, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 37: bd3762d7-270d-4760-8fb3-d829ca45278a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 38: c86d5194-4840-4dae-9c1c-0301003a5ab0, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 39: d552befb-48cc-4327-8f39-47d2d94f987c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 40: d6eadb3b-5ca8-4a6b-986e-35b550756111, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 41: df96023b-dcd9-4be2-afa0-c6c871159ebe, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 42: e0c42288-980c-4788-a014-c080d2e1926e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 43: e4db50ea-bda1-4566-b047-0ca50abc6f07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 44: e558417a-5123-4f6f-91e7-385c1c7ca9d4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 45: e7a950a2-e548-4f10-bf16-02ec848e0643, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 46: eb6d346f-1c60-4643-b960-40ec31596c45, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 47: ec868e65-fadf-4759-b23e-93fe37f2cc29, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 48: ef51e000-2659-4f25-8345-3de70a9cf4c4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 49: f7af7d09-40e4-419c-a49b-eae366689ebd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 50: fa755fe6-6739-40b9-8d84-6d0ea3b6d1ab, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 51: fe74f55b-0338-41d6-b267-4a201abe7285, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">1003</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.6685794Z" />
- <EventRecordID>1115</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
- <Data>
- 1: 040fa323-92b1-4baf-97a2-5b67feaefddb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 2: 0724cb7d-3437-4cb7-93cb-830375d0079d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 3: 0ad2ac98-7bb9-4201-8d92-312299201369, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 4: 1a9a717a-cf13-4ba5-83c3-0fe25fa868d5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 5: 221a02da-e2a1-4b75-864c-0a4410a33fdf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 6: 291ece0e-9c38-40ca-a9e1-32cc7ec19507, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 7: 2936d1d2-913a-4542-b54e-ce5a602a2a38, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 8: 2c293c26-a45a-4a2a-a350-c69a67097529, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 9: 2de67392-b7a7-462a-b1ca-108dd189f588, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 10: 2ffd8952-423e-4903-b993-72a1aa44cf82, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 11: 30a42c86-b7a0-4a34-8c90-ff177cb2acb7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 12: 345a5db0-d94f-4e3b-a0c0-7c42f7bc3ebf, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 13: 3502365a-f88a-4ba4-822a-5769d3073b65, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 14: 377333b1-8b5d-48d6-9679-1225c872d37c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 15: 3df374ef-d444-4494-a5a1-4b0d9fd0e203, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 16: 3f1afc82-f8ac-4f6c-8005-1d233e606eee, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 17: 49cd895b-53b2-4dc4-a5f7-b18aa019ad37, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 18: 4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c, 1, 1 [(0 )(1 )(2 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)(?)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(3 )]
- 19: 4f3da0d2-271d-4508-ae81-626b60809a38, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 20: 60b3ec1b-9545-4921-821f-311b129dd6f6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 21: 613d217f-7f13-4268-9907-1662339531cd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 22: 62f0c100-9c53-4e02-b886-a3528ddfe7f6, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 23: 6365275e-368d-46ca-a0ef-fc0404119333, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 24: 721f9237-9341-4453-a661-09e8baa6cca5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 25: 73111121-5638-40f6-bc11-f1d7b0d64300, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 26: 7a802526-4c94-4bd1-ba14-835a1aca2120, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 27: 7cb546c0-c7d5-44d8-9a5c-69ecdd782b69, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 28: 82bbc092-bc50-4e16-8e18-b74fc486aec3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 29: 8ab9bdd1-1f67-4997-82d9-8878520837d9, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 30: 8b351c9c-f398-4515-9900-09df49427262, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 31: 90da7373-1c51-430b-bf26-c97e9c5cdc31, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 32: 95dca82f-385d-4d39-b85b-5c73fa285d6f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 33: a48938aa-62fa-4966-9d44-9f04da3f72f2, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 34: b0773a15-df3a-4312-9ad2-83d69648e356, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 35: b4bfe195-541e-4e64-ad23-6177f19e395e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 36: b68e61d2-68ca-4757-be45-0cc2f3e68eee, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 37: bd3762d7-270d-4760-8fb3-d829ca45278a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 38: c86d5194-4840-4dae-9c1c-0301003a5ab0, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 39: d552befb-48cc-4327-8f39-47d2d94f987c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 40: d6eadb3b-5ca8-4a6b-986e-35b550756111, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 41: df96023b-dcd9-4be2-afa0-c6c871159ebe, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 42: e0c42288-980c-4788-a014-c080d2e1926e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 43: e4db50ea-bda1-4566-b047-0ca50abc6f07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 44: e558417a-5123-4f6f-91e7-385c1c7ca9d4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 45: e7a950a2-e548-4f10-bf16-02ec848e0643, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 46: eb6d346f-1c60-4643-b960-40ec31596c45, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 47: ec868e65-fadf-4759-b23e-93fe37f2cc29, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 48: ef51e000-2659-4f25-8345-3de70a9cf4c4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 49: f7af7d09-40e4-419c-a49b-eae366689ebd, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 50: fa755fe6-6739-40b9-8d84-6d0ea3b6d1ab, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- 51: fe74f55b-0338-41d6-b267-4a201abe7285, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
- </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:48
- Event ID: 1066
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- Initialization status for service objects.
- C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">1066</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.5843539Z" />
- <EventRecordID>1114</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
- C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
- </Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:48
- Event ID: 16394
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- Offline downlevel migration succeeded.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="49152">16394</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.5531111Z" />
- <EventRecordID>1113</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-Security-SPP
- Date: 24/04/2021 16:05:48
- Event ID: 900
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The Software Protection service is starting.
- Parameters:TriggerStarted:6
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
- <EventID Qualifiers="16384">900</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:48.3994991Z" />
- <EventRecordID>1112</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- <Data>TriggerStarted:6</Data>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-WMI
- Date: 24/04/2021 16:05:47
- Event ID: 5611
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: DESKTOP-T3O9TSS
- Description:
- The Windows Management Instrumentation service has detected an inconsistent system shutdown.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
- <EventID>5611</EventID>
- <Version>2</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:47.3248736Z" />
- <EventRecordID>1111</EventRecordID>
- <Correlation />
- <Execution ProcessID="3472" ThreadID="3848" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-WMI
- Date: 24/04/2021 16:05:46
- Event ID: 5615
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: DESKTOP-T3O9TSS
- Description:
- Windows Management Instrumentation Service started sucessfully
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
- <EventID>5615</EventID>
- <Version>2</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:46.6639830Z" />
- <EventRecordID>1110</EventRecordID>
- <Correlation />
- <Execution ProcessID="3472" ThreadID="3704" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- </EventData>
- </Event>
- Log Name: Application
- Source: Microsoft-Windows-User Profiles Service
- Date: 24/04/2021 16:05:45
- Event ID: 1531
- Task Category: None
- Level: Information
- Keywords:
- User: SYSTEM
- Computer: DESKTOP-T3O9TSS
- Description:
- The User Profile Service has started successfully.
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}" />
- <EventID>1531</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x8000000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:45.9071201Z" />
- <EventRecordID>1109</EventRecordID>
- <Correlation />
- <Execution ProcessID="1696" ThreadID="1772" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security UserID="S-1-5-18" />
- </System>
- <EventData>
- </EventData>
- </Event>
- Log Name: Application
- Source: IntelDalJhi
- Date: 24/04/2021 16:05:46
- Event ID: 0
- Task Category: None
- Level: Information
- Keywords: Classic
- User: N/A
- Computer: DESKTOP-T3O9TSS
- Description:
- The description for Event ID 0 from source IntelDalJhi cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
- If the event originated on another computer, the display information had to be saved with the event.
- The following information was included with the event:
- The specified resource type cannot be found in the image file
- Event Xml:
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
- <Provider Name="IntelDalJhi" />
- <EventID Qualifiers="16384">0</EventID>
- <Version>0</Version>
- <Level>4</Level>
- <Task>0</Task>
- <Opcode>0</Opcode>
- <Keywords>0x80000000000000</Keywords>
- <TimeCreated SystemTime="2021-04-24T14:05:46.7099773Z" />
- <EventRecordID>1108</EventRecordID>
- <Correlation />
- <Execution ProcessID="0" ThreadID="0" />
- <Channel>Application</Channel>
- <Computer>DESKTOP-T3O9TSS</Computer>
- <Security />
- </System>
- <EventData>
- </EventData>
- </Event>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement