seunghoyang
New Member
- Joined
- Mar 16, 2010
- Messages
- 14
Log Name: Security
Source: Microsoft-Windows-Eventlog
Date: 3/18/2010 5:37:08 PM
Event ID: 1101
Task Category: Event processing
Level: Error
Keywords: Audit Success
User: N/A
Computer: Seungho-PC
Description:
Audit events have been dropped by the transport. 0
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
<EventID>1101</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>101</Task>
<Opcode>0</Opcode>
<Keywords>0x4020000000000000</Keywords>
<TimeCreated SystemTime="2010-03-18T08:37:08.209227600Z" />
<EventRecordID>12400</EventRecordID>
<Correlation />
<Execution ProcessID="856" ThreadID="1212" />
<Channel>Security</Channel>
<Computer>Seungho-PC</Computer>
<Security />
</System>
<UserData>
<AuditEventsDropped xmlns:auto-ns3="http://schemas.microsoft.com/win/2004/08/events" xmlns="http://manifests.microsoft.com/win/2004/08/windows/eventlog">
<Reason>0</Reason>
</AuditEventsDropped>
</UserData>
</Event>
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 3/18/2010 5:37:01 PM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (2)
User: SYSTEM
Computer: Seungho-PC
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2010-03-18T08:37:01.111215200Z" />
<EventRecordID>9982</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Seungho-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-HAL
Date: 3/18/2010 7:14:55 AM
Event ID: 12
Task Category: None
Level: Error
Keywords: (1)
User: N/A
Computer: Seungho-PC
Description:
The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-HAL" Guid="{63D1E632-95CC-4443-9312-AF927761D52A}" />
<EventID>12</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000001</Keywords>
<TimeCreated SystemTime="2010-03-17T22:14:55.150938100Z" />
<EventRecordID>9744</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="656" />
<Channel>System</Channel>
<Computer>Seungho-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="Count">1</Data>
<Data Name="FirstPage">12</Data>
<Data Name="LastPage">12</Data>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 3/18/2010 3:01:46 AM
Event ID: 1001
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: SEUNGHO-PC
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x000000be (0xfffff960000a6247, 0x2c6000011c074021, 0xfffff8800613b5f0, 0x000000000000000b). A dump was saved in: C:\Windows\Minidump\031810-19593-01.dmp. Report Id: 031810-19593-01.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
<EventID Qualifiers="16384">1001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2010-03-17T18:01:46.000000000Z" />
<EventRecordID>9629</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>SEUNGHO-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">0x000000be (0xfffff960000a6247, 0x2c6000011c074021, 0xfffff8800613b5f0, 0x000000000000000b)</Data>
<Data Name="param2">C:\Windows\Minidump\031810-19593-01.dmp</Data>
<Data Name="param3">031810-19593-01</Data>
</EventData>
</Event>