Event[0]: Log Name: Application Source: Desktop Window Manager Date: 2011-02-20T16:41:19.000 Event ID: 9009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Desktop Window Manager has exited with code (0x40010004) Event[1]: Log Name: Application Source: Microsoft-Windows-Winlogon Date: 2011-02-20T16:41:20.000 Event ID: 6000 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The winlogon notification subscriber was unavailable to handle a notification event. Event[2]: Log Name: Application Source: VSS Date: 2011-02-20T16:41:22.000 Event ID: 8224 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The VSS service is shutting down due to idle timeout. Event[3]: Log Name: Application Source: Bonjour Service Date: 2011-02-20T16:41:25.000 Event ID: 100 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Service stopped (0) Event[4]: Log Name: Application Source: Microsoft-Windows-User Profiles Service Date: 2011-02-20T16:41:25.514 Event ID: 1532 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Marcel-PC Description: The User Profile Service has stopped. Event[5]: Log Name: Application Source: Microsoft-Windows-EventSystem Date: 2011-02-20T16:45:06.000 Event ID: 4625 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Event[6]: Log Name: Application Source: Microsoft-Windows-User Profiles Service Date: 2011-02-20T16:45:06.957 Event ID: 1531 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Marcel-PC Description: The User Profile Service has started successfully. Event[7]: Log Name: Application Source: Bonjour Service Date: 2011-02-20T16:45:08.000 Event ID: 100 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Service started Event[8]: Log Name: Application Source: Microsoft-Windows-WMI Date: 2011-02-20T16:45:09.000 Event ID: 5615 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows Management Instrumentation Service started sucessfully Event[9]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T16:45:10.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[10]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T16:45:10.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[11]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T16:45:10.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[12]: Log Name: Application Source: Microsoft-Windows-WMI Date: 2011-02-20T16:45:13.000 Event ID: 5617 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows Management Instrumentation Service subsystems initialized successfully Event[13]: Log Name: Application Source: Microsoft-Windows-Winlogon Date: 2011-02-20T16:46:48.000 Event ID: 4101 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows license validated. Event[14]: Log Name: Application Source: Microsoft-Windows-Winlogon Date: 2011-02-20T16:46:48.000 Event ID: 6000 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The winlogon notification subscriber was unavailable to handle a notification event. Event[15]: Log Name: Application Source: iPod Service Date: 2011-02-20T16:47:03.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[16]: Log Name: Application Source: ESENT Date: 2011-02-20T16:47:03.000 Event ID: 102 Task: General Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (3568) Windows: The database engine (6.01.7600.0000) started a new instance (0). Event[17]: Log Name: Application Source: ESENT Date: 2011-02-20T16:47:03.000 Event ID: 300 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (3568) Windows: The database engine is initiating recovery steps. Event[18]: Log Name: Application Source: ESENT Date: 2011-02-20T16:47:03.000 Event ID: 301 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (3568) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Event[19]: Log Name: Application Source: ESENT Date: 2011-02-20T16:47:07.000 Event ID: 302 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (3568) Windows: The database engine has successfully completed recovery steps. Event[20]: Log Name: Application Source: Microsoft-Windows-Search Date: 2011-02-20T16:47:14.000 Event ID: 1003 Task: Search service Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Windows Search Service started. Event[21]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T16:47:37.000 Event ID: 900 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service is starting. Event[22]: Log Name: Application Source: SecurityCenter Date: 2011-02-20T16:47:49.000 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Windows Security Center Service has started. Event[23]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T16:47:51.000 Event ID: 1066 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Initialization status for service objects. C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 Event[24]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T16:47:51.000 Event ID: 1003 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has completed licensing status check. Application Id=55c92734-d682-4d71-983e-d6ec3f16059f Licensing Status= 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 3: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] Event[25]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T16:47:51.000 Event ID: 902 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has started. 6.1.7600.16385 Event[26]: Log Name: Application Source: Microsoft-Windows-Search Date: 2011-02-20T16:50:15.000 Event ID: 3036 Task: Gatherer Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The content source cannot be accessed. Context: Application, SystemIndex Catalog Details: The object was not found. (HRESULT : 0x80041201) (0x80041201) Event[27]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T16:52:52.000 Event ID: 903 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has stopped. Event[28]: Log Name: Application Source: Microsoft-Windows-EventSystem Date: 2011-02-20T17:43:52.000 Event ID: 4625 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Event[29]: Log Name: Application Source: Microsoft-Windows-User Profiles Service Date: 2011-02-20T17:43:52.087 Event ID: 1531 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Marcel-PC Description: The User Profile Service has started successfully. Event[30]: Log Name: Application Source: Microsoft-Windows-Winlogon Date: 2011-02-20T17:43:59.000 Event ID: 4101 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows license validated. Event[31]: Log Name: Application Source: Microsoft-Windows-Winlogon Date: 2011-02-20T17:43:59.000 Event ID: 6000 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The winlogon notification subscriber was unavailable to handle a notification event. Event[32]: Log Name: Application Source: Bonjour Service Date: 2011-02-20T17:44:09.000 Event ID: 100 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Service started Event[33]: Log Name: Application Source: Microsoft-Windows-WMI Date: 2011-02-20T17:44:11.000 Event ID: 5615 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows Management Instrumentation Service started sucessfully Event[34]: Log Name: Application Source: Windows Error Reporting Date: 2011-02-20T17:44:13.000 Event ID: 1001 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Fault bucket , type 0 Event Name: LiveKernelEvent Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\LiveKernelReports\WATCHDOG\WD-20110220-1742.dmp C:\Windows\Temp\WER-25849-0.sysdata.xml C:\Windows\Temp\WERB4FC.tmp.WERInternalMetadata.xml These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Kernel_0_0_cab_02f4b598 Analysis symbol: Rechecking for solution: 0 Report Id: 03bf3920-3cac-11e0-ad02-002215d4c340 Report Status: 4 Event[35]: Log Name: Application Source: Microsoft-Windows-WMI Date: 2011-02-20T17:44:14.000 Event ID: 5611 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Windows Management Instrumentation service has detected an inconsistent system shutdown. Event[36]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T17:44:14.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[37]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T17:44:14.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[38]: Log Name: Application Source: SignInAssistant Date: 2011-02-20T17:44:14.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[39]: Log Name: Application Source: Microsoft-Windows-WMI Date: 2011-02-20T17:44:32.000 Event ID: 5617 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows Management Instrumentation Service subsystems initialized successfully Event[40]: Log Name: Application Source: Windows Error Reporting Date: 2011-02-20T17:44:35.000 Event ID: 1001 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\022011-24195-01.dmp C:\Users\Marcel\AppData\Local\Temp\WER-48812-0.sysdata.xml These files may be available here: C:\Users\Marcel\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0bd10d48 Analysis symbol: Rechecking for solution: 0 Report Id: 022011-24195-01 Report Status: 0 Event[41]: Log Name: Application Source: iPod Service Date: 2011-02-20T17:44:39.000 Event ID: 0 Task: None Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: N/A Event[42]: Log Name: Application Source: ESENT Date: 2011-02-20T17:44:41.000 Event ID: 102 Task: General Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (4296) Windows: The database engine (6.01.7600.0000) started a new instance (0). Event[43]: Log Name: Application Source: ESENT Date: 2011-02-20T17:44:42.000 Event ID: 300 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (4296) Windows: The database engine is initiating recovery steps. Event[44]: Log Name: Application Source: ESENT Date: 2011-02-20T17:44:42.000 Event ID: 301 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (4296) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS054CF.log. Event[45]: Log Name: Application Source: ESENT Date: 2011-02-20T17:44:49.000 Event ID: 301 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (4296) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Event[46]: Log Name: Application Source: ESENT Date: 2011-02-20T17:44:52.000 Event ID: 302 Task: Logging/Recovery Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Windows (4296) Windows: The database engine has successfully completed recovery steps. Event[47]: Log Name: Application Source: Microsoft-Windows-Search Date: 2011-02-20T17:45:07.000 Event ID: 1003 Task: Search service Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Windows Search Service started. Event[48]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T17:46:40.000 Event ID: 900 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service is starting. Event[49]: Log Name: Application Source: SecurityCenter Date: 2011-02-20T17:46:40.000 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Windows Security Center Service has started. Event[50]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T17:46:41.000 Event ID: 1066 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: Initialization status for service objects. C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 Event[51]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T17:46:42.000 Event ID: 1003 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has completed licensing status check. Application Id=55c92734-d682-4d71-983e-d6ec3f16059f Licensing Status= 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 3: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] Event[52]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T17:46:42.000 Event ID: 902 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has started. 6.1.7600.16385 Event[53]: Log Name: Application Source: Microsoft-Windows-Search Date: 2011-02-20T17:48:10.000 Event ID: 3036 Task: Gatherer Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The content source cannot be accessed. Context: Application, SystemIndex Catalog Details: The object was not found. (HRESULT : 0x80041201) (0x80041201) Event[54]: Log Name: Application Source: Microsoft-Windows-Security-SPP Date: 2011-02-20T17:51:42.000 Event ID: 903 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Marcel-PC Description: The Software Protection service has stopped.