Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 25/07/2016 14:00:59
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DESKTOP-5F99R7M
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xffffb00d8899098b, 0x00000000000000ff, 0x0000000000000021, 0xfffff8036f89c6ff). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 31bd18a8-b2e9-43ad-ae6d-5735603be403.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2016-07-25T13:00:59.871244200Z" />
<EventRecordID>2909</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x0000000a (0xffffb00d8899098b, 0x00000000000000ff, 0x0000000000000021, 0xfffff8036f89c6ff)</Data>
<Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
<Data Name="param3">31bd18a8-b2e9-43ad-ae6d-5735603be403</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 25/07/2016 14:00:54
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (70368744177664),(2)
User: SYSTEM
Computer: DESKTOP-5F99R7M
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>3</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000400000000002</Keywords>
<TimeCreated SystemTime="2016-07-25T13:00:54.691573000Z" />
<EventRecordID>2892</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">10</Data>
<Data Name="BugcheckParameter1">0xffffb00d8899098b</Data>
<Data Name="BugcheckParameter2">0xff</Data>
<Data Name="BugcheckParameter3">0x21</Data>
<Data Name="BugcheckParameter4">0xfffff8036f89c6ff</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
</EventData>
</Event>
Log Name: System
Source: EventLog
Date: 25/07/2016 14:00:58
Event ID: 6008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DESKTOP-5F99R7M
Description:
The previous system shutdown at 13:23:28 on ?25/?07/?2016 was unexpected.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2016-07-25T13:00:58.543067800Z" />
<EventRecordID>2882</EventRecordID>
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security />
</System>
<EventData>
<Data>13:23:28</Data>
<Data>?25/?07/?2016</Data>
<Data>
</Data>
<Data>
</Data>
<Data>5</Data>
<Data>
</Data>
<Data>
</Data>
<Binary>E0070700010019000D0017001C000402E0070700010019000C0017001C0004023C0000003C000000000000000000000000000000000000000100000000000000</Binary>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 25/07/2016 13:23:29
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DESKTOP-5F99R7M
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xffffd1a3f6a7b7b2, 0x00000000000000ff, 0x0000000000000012, 0xfffff800628946ff). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: e849c1af-157a-482f-ac51-59b372384da8.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2016-07-25T12:23:29.829321400Z" />
<EventRecordID>2867</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x0000000a (0xffffd1a3f6a7b7b2, 0x00000000000000ff, 0x0000000000000012, 0xfffff800628946ff)</Data>
<Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
<Data Name="param3">e849c1af-157a-482f-ac51-59b372384da8</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-Kernel-PnP
Date: 25/07/2016 13:23:28
Event ID: 219
Task Category: (212)
Level: Warning
Keywords:
User: SYSTEM
Computer: DESKTOP-5F99R7M
Description:
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\{d184cfd3-37bb-11e6-9bd2-806e6f6e6963}#0000000008100000.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
<EventID>219</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>212</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2016-07-25T12:23:28.519016200Z" />
<EventRecordID>2863</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="376" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="DriverNameLength">70</Data>
<Data Name="DriverName">SWD\WPDBUSENUM\{d184cfd3-37bb-11e6-9bd2-806e6f6e6963}#0000000008100000</Data>
<Data Name="Status">3221226341</Data>
<Data Name="FailureNameLength">14</Data>
<Data Name="FailureName">\Driver\WudfRd</Data>
<Data Name="Version">0</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 25/07/2016 13:23:24
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (70368744177664),(2)
User: SYSTEM
Computer: DESKTOP-5F99R7M
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>3</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000400000000002</Keywords>
<TimeCreated SystemTime="2016-07-25T12:23:24.734862200Z" />
<EventRecordID>2850</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">10</Data>
<Data Name="BugcheckParameter1">0xffffd1a3f6a7b7b2</Data>
<Data Name="BugcheckParameter2">0xff</Data>
<Data Name="BugcheckParameter3">0x12</Data>
<Data Name="BugcheckParameter4">0xfffff800628946ff</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 25/07/2016 03:30:48
Event ID: 10016
Task Category: None
Level: Error
Keywords: Classic
User: SYSTEM
Computer: DESKTOP-5F99R7M
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="0">10016</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2016-07-25T02:30:48.544122100Z" />
<EventRecordID>2750</EventRecordID>
<Correlation />
<Execution ProcessID="860" ThreadID="5692" />
<Channel>System</Channel>
<Computer>DESKTOP-5F99R7M</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="param1">application-specific</Data>
<Data Name="param2">Local</Data>
<Data Name="param3">Activation</Data>
<Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
<Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
<Data Name="param6">NT AUTHORITY</Data>
<Data Name="param7">SYSTEM</Data>
<Data Name="param8">S-1-5-18</Data>
<Data Name="param9">LocalHost (Using LRPC)</Data>
<Data Name="param10">Unavailable</Data>
<Data Name="param11">Unavailable</Data>
</EventData>
</Event>