Log Name: Application
Source: Microsoft-Windows-Search
Date: 6/2/2022 8:58:05 AM
Event ID: 10024
Task Category: Gatherer
Level: Warning
Keywords: Classic
User: N/A
Computer: dunx1
Description:
The filter host process 20240 did not respond and is being forcibly terminated.
Event Xml:
10024
0
3
3
0
0x80000000000000
10844
Application
dunx1
20240
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 6/2/2022 8:57:18 AM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: DUNX1\runle
Computer: dunx1
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user dunx1\runle SID (S-1-5-21-3465743884-2908752811-2602381911-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
10016
0
3
0
0
0x8080000000000000
94644
System
dunx1
application-specific
Local
Activation
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
dunx1
runle
S-1-5-21-3465743884-2908752811-2602381911-1001
LocalHost (Using LRPC)
Unavailable
Unavailable
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 6/2/2022 8:57:17 AM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: DUNX1\runle
Computer: dunx1
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user dunx1\runle SID (S-1-5-21-3465743884-2908752811-2602381911-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
10016
0
3
0
0
0x8080000000000000
94642
System
dunx1
application-specific
Local
Activation
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
dunx1
runle
S-1-5-21-3465743884-2908752811-2602381911-1001
LocalHost (Using LRPC)
Unavailable
Unavailable
Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
Source: Microsoft-Windows-Kernel-EventTracing
Date: 6/2/2022 8:46:44 AM
Event ID: 3
Task Category: Session
Level: Error
Keywords: Session
User: SYSTEM
Computer: dunx1
Description:
Session "PerfDiag Logger" stopped due to the following error: 0xC0000188
Event Xml:
3
1
2
2
14
0x8000000000000010
125
Microsoft-Windows-Kernel-EventTracing/Admin
dunx1
PerfDiag Logger
C:\Windows\system32\WDI\LogFiles\ShutdownPerfDiagLogger.etl
3221225864
41943168
0
Log Name: Microsoft-Windows-Kernel-EventTracing/Admin
Source: Microsoft-Windows-Kernel-EventTracing
Date: 6/2/2022 8:46:44 AM
Event ID: 4
Task Category: Logging
Level: Warning
Keywords: Session
User: SYSTEM
Computer: dunx1
Description:
The maximum file size for session "PerfDiag Logger" has been reached. As a result, events might be lost (not logged) to file "C:\Windows\system32\WDI\LogFiles\ShutdownPerfDiagLogger.etl". The maximum files size is currently set to 20971520 bytes.
Event Xml:
4
0
3
1
10
0x8000000000000010
124
Microsoft-Windows-Kernel-EventTracing/Admin
dunx1
PerfDiag Logger
C:\Windows\system32\WDI\LogFiles\ShutdownPerfDiagLogger.etl
3221225864
41943168
20971520
Log Name: Application
Source: VSS
Date: 6/2/2022 8:38:09 AM
Event ID: 8194
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: dunx1
Description:
Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3fd91e-2858-4287-84a0-f02420e75295}
Event Xml:
8194
0
2
0
0
0x80000000000000
10838
Application
dunx1
0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3fd91e-2858-4287-84a0-f02420e75295}
2D20436F64653A20575254575254494330303030313238372D2043616C6C3A20575254575254494330303030313234312D205049443A202030303030353236342D205449443A202030303030353637362D20434D443A2020433A5C57696E646F77735C73797374656D33325C737663686F73742E657865202D6B204E6574776F726B53657276696365202D70202020202D20557365723A204E616D653A204E5420415554484F524954595C4E4554574F524B20534552564943452C205349443A532D312D352D3230
Log Name: Application
Source: VSS
Date: 6/2/2022 8:24:55 AM
Event ID: 8194
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: dunx1
Description:
Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3fd91e-2858-4287-84a0-f02420e75295}
Event Xml:
8194
0
2
0
0
0x80000000000000
10805
Application
dunx1
0x80070005, Access is denied.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {0a3fd91e-2858-4287-84a0-f02420e75295}
2D20436F64653A20575254575254494330303030313238372D2043616C6C3A20575254575254494330303030313234312D205049443A202030303030353236342D205449443A202030303031313834302D20434D443A2020433A5C57696E646F77735C73797374656D33325C737663686F73742E657865202D6B204E6574776F726B53657276696365202D70202020202D20557365723A204E616D653A204E5420415554484F524954595C4E4554574F524B20534552564943452C205349443A532D312D352D3230
Log Name: Microsoft-Windows-User Device Registration/Admin
Source: Microsoft-Windows-User Device Registration
Date: 6/2/2022 8:24:16 AM
Event ID: 360
Task Category: None
Level: Warning
Keywords:
User: DUNX1\runle
Computer: dunx1
Description:
Windows Hello for Business provisioning will not be launched.
Device is AAD joined ( AADJ or DJ++ ): Not Tested
User has logged on with AAD credentials: No
Windows Hello for Business policy is enabled: Not Tested
Windows Hello for Business post-logon provisioning is enabled: Not Tested
Local computer meets Windows hello for business hardware requirements: Not Tested
User is not connected to the machine via Remote Desktop: Yes
User certificate for on premise auth policy is enabled: Not Tested
Machine is governed by none policy.
Cloud trust for on premise auth policy is enabled: Not Tested
User account has Cloud TGT: Not Tested
See https://go.microsoft.com/fwlink/?linkid=832647 for more details.
Event Xml:
360
0
3
0
0
0x8000000000000000
62
Microsoft-Windows-User Device Registration/Admin
dunx1
Windows Hello for Business provisioning will not be launched.
Not Tested
No
Not Tested
Not Tested
Not Tested
Yes
Not Tested
none
Not Tested
Not Tested
Log Name: System
Source: Server
Date: 6/2/2022 8:24:15 AM
Event ID: 2505
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: dunx1
Description:
The server could not bind to the transport \Device\NetBT_Tcpip_{A4CD1237-8044-4F00-A723-77B1F058E076} because another computer on the network has the same name. The server could not start.
Event Xml:
2505
0
2
0
0
0x80000000000000
93751
System
dunx1
\Device\NetBT_Tcpip_{A4CD1237-8044-4F00-A723-77B1F058E076}
34000000
Log Name: System
Source: Netwtw10
Date: 6/2/2022 8:24:13 AM
Event ID: 6062
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: dunx1
Description:
The description for Event ID 6062 from source Netwtw10 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
If the event originated on another computer, the display information had to be saved with the event.
The following information was included with the event:
\Device\NDMP1
Intel(R) Wi-Fi 6E AX211 160MHz
The system cannot find the file specified
Event Xml:
6062
0
3
0
0
0x80000000000000
93750
System
dunx1
\Device\NDMP1
Intel(R) Wi-Fi 6E AX211 160MHz
000000000200300000000000AE170080000000000000000000000000000000000000000000000000
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 6/2/2022 8:24:12 AM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: LOCAL SERVICE
Computer: dunx1
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
10016
0
3
0
0
0x8080000000000000
93742
System
dunx1
application-specific
Local
Activation
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
NT AUTHORITY
LOCAL SERVICE
S-1-5-19
LocalHost (Using LRPC)
Unavailable
Unavailable
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 6/2/2022 8:24:12 AM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: LOCAL SERVICE
Computer: dunx1
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
10016
0
3
0
0
0x8080000000000000
93741
System
dunx1
application-specific
Local
Activation
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
NT AUTHORITY
LOCAL SERVICE
S-1-5-19
LocalHost (Using LRPC)
Unavailable
Unavailable
Log Name: System
Source: Microsoft-Windows-NDIS
Date: 6/2/2022 8:24:11 AM
Event ID: 10317
Task Category: PnP
Level: Error
Keywords: (16384),(16),(4),(2)
User: N/A
Computer: dunx1
Description:
Miniport Microsoft Wi-Fi Direct Virtual Adapter #2, {ac07c9db-fcdb-4f46-a516-fb0bdceb1c27}, had event Fatal error: The miniport has failed a power transition to operational power
Event Xml:
10317
0
2
2
0
0x2000000000004016
93720
System
dunx1
{ac07c9db-fcdb-4f46-a516-fb0bdceb1c27}
12
19985273135824896
Microsoft Wi-Fi Direct Virtual Adapter #2
74
Log Name: Microsoft-Windows-Dhcp-Client/Admin
Source: Microsoft-Windows-Dhcp-Client
Date: 6/2/2022 8:24:11 AM
Event ID: 1003
Task Category: Address Configuration State Event
Level: Warning
Keywords: (1)
User: LOCAL SERVICE
Computer: dunx1
Description:
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 0x2C0DA7FFA113. The following error occurred: 0x79. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
Event Xml:
1003
0
3
3
77
0x4000000000000001
245
Microsoft-Windows-Dhcp-Client/Admin
dunx1
6
2C0DA7FFA113
121