Level Date and Time Source Event ID Task Category Information 1/14/2013 12:42:59 PM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 12:42:59 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 12:42:59 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:42:59 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:42:59 PM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 12:42:57 PM VSS 8211 None Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode. Operation: Initializing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Information 1/14/2013 12:42:56 PM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 12:42:47 PM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 12:41:57 PM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 12:41:55 PM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 12:41:53 PM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 12:41:52 PM ESENT 302 Logging/Recovery Windows (1196) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 12:41:49 PM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 12:41:50 PM ESENT 301 Logging/Recovery Windows (1196) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 12:41:50 PM ESENT 300 Logging/Recovery Windows (1196) Windows: The database engine is initiating recovery steps. Information 1/14/2013 12:41:50 PM ESENT 102 General Windows (1196) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 12:41:49 PM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 12:41:40 PM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 12:41:40 PM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 12:37:48 PM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Warning 1/14/2013 12:37:46 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:37:46 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:37:46 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 12:37:46 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Error 1/14/2013 12:37:37 PM Application Error 1000 (100) "Faulting application name: unetbootin-xpud-windows-387.exe, version: 1.1.1.1, time stamp: 0x4b62785b Faulting module name: unetbootin-xpud-windows-387.exe, version: 1.1.1.1, time stamp: 0x4b62785b Exception code: 0xc0000005 Fault offset: 0x0083c54a Faulting process id: 0x6e4 Faulting application start time: 0x01cdf283b9001e46 Faulting application path: C:\Users\Ada\Desktop\unetbootin-xpud-windows-387.exe Faulting module path: C:\Users\Ada\Desktop\unetbootin-xpud-windows-387.exe Report Id: 7761e89e-5e79-11e2-9088-c80aa98fda69" Information 1/14/2013 12:15:40 PM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 12:15:39 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 12:15:39 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:15:39 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:15:39 PM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 12:15:38 PM VSS 8211 None Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode. Operation: Initializing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Information 1/14/2013 12:15:37 PM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 12:15:28 PM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 12:14:25 PM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 12:14:20 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:14:20 PM Desktop Window Manager 9009 None The Desktop Window Manager has exited with code (0x40010004) Information 1/14/2013 12:12:58 PM Microsoft-Windows-Security-SPP 902 None "The Software Protection service has started. 6.1.7601.17514" Information 1/14/2013 12:12:58 PM Microsoft-Windows-Security-SPP 1003 None "The Software Protection service has completed licensing status check. Application Id=55c92734-d682-4d71-983e-d6ec3f16059f Licensing Status= 1: 01f5fc37-a99e-45c5-b65e-d762f3518ead, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 2e7d060d-4714-40f2-9896-1e4f15b612ad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 3b965dfc-31d9-4903-886f-873a0382776c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 586bc076-c93d-429a-afe5-a69fbc644e88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 5e35dc43-389b-47c5-b889-2088b06738cb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: 6a7d5d8a-92af-4e6a-af4b-8fddaec800e5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: 9ab82e0c-ffc9-4107-baa1-c65a8bd3ccc3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: 9f83d90f-a151-4665-ae69-30b3f63ec659, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: a63275f4-530c-48a7-b0d3-4f00d688d151, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: b8a4bb91-69b1-460d-93f8-40e0670af04a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: d2c04e90-c3dd-4260-b0f3-f845f5d27d64, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 13: e68b141f-4dfa-4387-b3b7-e65c4889216e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 14: ee4e1629-bcdc-4b42-a68f-b92e135f78d7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 15: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 16: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] " Information 1/14/2013 12:12:58 PM Microsoft-Windows-Security-SPP 1066 None "Initialization status for service objects. C:\windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 " Information 1/14/2013 12:12:53 PM Microsoft-Windows-Security-SPP 900 None "The Software Protection service is starting. " Information 1/14/2013 12:12:46 PM gupdate 0 None "The description for Event ID 0 from source gupdate cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: Service stopped " Information 1/14/2013 12:11:59 PM Windows Error Reporting 1001 None "Fault bucket 3237251052, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: toshibaservicestation.exe P2: 2.2.4059.23056 P3: 4d55a0a0 P4: System.Windows.Forms P5: 2.0.0.0 P6: 4f682206 P7: 16e7 P8: 259 P9: System.ComponentModel.Win32 P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WER94FE.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_toshibaservicest_1d681665793fafadef81d35f5e7844d29482d5f_0d35a025 Analysis symbol: Rechecking for solution: 0 Report Id: e0e36642-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:11:24 PM Windows Error Reporting 1001 None "Fault bucket 3348744319, type 1 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: chrome.exe P2: 24.0.1312.52 P3: 50eb47e3 P4: chrome.dll P5: 24.0.1312.52 P6: 50eb4775 P7: 80000003 P8: 00597591 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERD77.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_chrome.exe_b7ee6fc7b145939458ca0a7fa8dbb2fd4931585_0cf119f5 Analysis symbol: Rechecking for solution: 0 Report Id: cb637bc3-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Error 1/14/2013 12:11:20 PM Application Error 1000 (100) "Faulting application name: chrome.exe, version: 24.0.1312.52, time stamp: 0x50eb47e3 Faulting module name: chrome.dll, version: 24.0.1312.52, time stamp: 0x50eb4775 Exception code: 0x80000003 Fault offset: 0x00597591 Faulting process id: 0xb20 Faulting application start time: 0x01cdf2828b82cac2 Faulting application path: C:\Users\Ada\AppData\Local\Google\Chrome\Application\chrome.exe Faulting module path: C:\Users\Ada\AppData\Local\Google\Chrome\Application\24.0.1312.52\chrome.dll Report Id: cb637bc3-5e75-11e2-b7da-c80aa98fda69" Information 1/14/2013 12:11:06 PM Windows Error Reporting 1001 None "Fault bucket 3371106675, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: mom.exe P2: 2.0.0.0 P3: 49ef8e68 P4: System P5: 2.0.0.0 P6: 503f053d P7: 165d P8: f9 P9: AMAG3AACMAWG2XAF344U21ACVE5PSTKL P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERA073.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mom.exe_b3e17a845ec1866852d35e2d1849b935608969a_04dcd42f Analysis symbol: Rechecking for solution: 0 Report Id: bb927714-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:11:06 PM Windows Error Reporting 1001 None "Fault bucket 3371106675, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: mom.exe P2: 2.0.0.0 P3: 49ef8e68 P4: System P5: 2.0.0.0 P6: 503f053d P7: 165d P8: f9 P9: AMAG3AACMAWG2XAF344U21ACVE5PSTKL P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERB73D.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mom.exe_b3e17a845ec1866852d35e2d1849b935608969a_0dccd42f Analysis symbol: Rechecking for solution: 0 Report Id: bf0f1b1a-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:11:06 PM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERA1F9.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0ca4d42f Analysis symbol: Rechecking for solution: 0 Report Id: bbc473fa-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:11:06 PM Windows Error Reporting 1001 None "Fault bucket 62940440, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: taskeng.exe P2: 6.1.7601.17514 P3: 4ce79d2c P4: ntdll.dll P5: 6.1.7601.17725 P6: 4ec4aa8e P7: c0000005 P8: 000000000009970a P9: P10: Attached files: These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_taskeng.exe_f14746ebf79a8cc00773421bfa23c946ba2b9_0ddcd21d Analysis symbol: Rechecking for solution: 0 Report Id: b76d9bf8-5e75-11e2-b7da-c80aa98fda69 Report Status: 0" Error 1/14/2013 12:10:53 PM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xacc Faulting application start time: 0x01cdf28277b300fb Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: bbc473fa-5e75-11e2-b7da-c80aa98fda69" Information 1/14/2013 12:10:48 PM Windows Error Reporting 1001 None "The description for Event ID 1001 from source Windows Error Reporting cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: 0 APPCRASH Not available 0 taskeng.exe 6.1.7601.17514 4ce79d2c ntdll.dll 6.1.7601.17725 4ec4aa8e c0000005 000000000009970a C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_taskeng.exe_f14746ebf79a8cc00773421bfa23c946ba2b9_06448d7f 0 b76d9bf8-5e75-11e2-b7da-c80aa98fda69 4 The handle is invalid " Error 1/14/2013 12:10:46 PM Application Error 1000 (100) "Faulting application name: taskeng.exe, version: 6.1.7601.17514, time stamp: 0x4ce79d2c Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x000000000009970a Faulting process id: 0xb10 Faulting application start time: 0x01cdf28277c86d5e Faulting application path: C:\windows\system32\taskeng.exe Faulting module path: C:\windows\SYSTEM32\ntdll.dll Report Id: b76d9bf8-5e75-11e2-b7da-c80aa98fda69" Information 1/14/2013 12:10:44 PM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 12:10:43 PM Desktop Window Manager 9003 None The Desktop Window Manager was unable to start because a composited theme is not in use Information 1/14/2013 12:10:43 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:10:43 PM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 12:10:41 PM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 12:10:38 PM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 12:10:39 PM ESENT 302 Logging/Recovery Windows (1188) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 12:10:39 PM ESENT 301 Logging/Recovery Windows (1188) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 12:10:39 PM ESENT 300 Logging/Recovery Windows (1188) Windows: The database engine is initiating recovery steps. Information 1/14/2013 12:10:39 PM ESENT 102 General Windows (1188) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 12:10:38 PM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 12:10:30 PM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 12:10:30 PM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 12:02:56 PM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 12:02:54 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:02:54 PM Desktop Window Manager 9009 None The Desktop Window Manager has exited with code (0x40010004) Information 1/14/2013 12:01:52 PM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERCCEF.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0fd8fbdb Analysis symbol: Rechecking for solution: 0 Report Id: 718fb6cd-5e74-11e2-bbff-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:01:51 PM Windows Error Reporting 1001 None "Fault bucket 64903229, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: TCrdMain.exe P2: 2.0.2.6 P3: 4b8df51d P4: ntdll.dll P5: 6.1.7601.17725 P6: 4ec4aa8e P7: c0000005 P8: 000000000009970a P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERB75C.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_TCrdMain.exe_adfb51814ddd1ed6ae865588868fa0ae1d982461_0d20f7d5 Analysis symbol: Rechecking for solution: 0 Report Id: 6decfcc3-5e74-11e2-bbff-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:01:51 PM Windows Error Reporting 1001 None "Fault bucket 3371106675, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: mom.exe P2: 2.0.0.0 P3: 49ef8e68 P4: System P5: 2.0.0.0 P6: 503f053d P7: 165d P8: f9 P9: AMAG3AACMAWG2XAF344U21ACVE5PSTKL P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERD171.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mom.exe_b3e17a845ec1866852d35e2d1849b935608969a_0c7cf7d5 Analysis symbol: Rechecking for solution: 0 Report Id: 724bc383-5e74-11e2-bbff-c80aa98fda69 Report Status: 0" Information 1/14/2013 12:01:46 PM Windows Error Reporting 1001 None "The description for Event ID 1001 from source Windows Error Reporting cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: 0 StartupRepairOnline Not available 0 6.1.7600.16385 6.1.7600.16385 TOSHIBA 12 0 ExternalMedia 1 NoBootFailure C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7600.16385_3731ca9d4181857a7c2fafd795936547595097_cab_0ab0e60a 0 6cbc0cd9-5e74-11e2-bbff-c80aa98fda69 4 The handle is invalid " Error 1/14/2013 12:01:39 PM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xa98 Faulting application start time: 0x01cdf2812ce9a41a Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: 718fb6cd-5e74-11e2-bbff-c80aa98fda69" Error 1/14/2013 12:01:33 PM Application Error 1000 (100) "Faulting application name: TCrdMain.exe, version: 2.0.2.6, time stamp: 0x4b8df51d Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x000000000009970a Faulting process id: 0xc48 Faulting application start time: 0x01cdf2812fe8abeb Faulting application path: C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe Faulting module path: C:\windows\SYSTEM32\ntdll.dll Report Id: 6decfcc3-5e74-11e2-bbff-c80aa98fda69" Information 1/14/2013 12:01:30 PM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 12:01:28 PM Desktop Window Manager 9003 None The Desktop Window Manager was unable to start because a composited theme is not in use Information 1/14/2013 12:01:28 PM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 12:01:28 PM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 12:01:26 PM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 12:01:23 PM ESENT 302 Logging/Recovery Windows (1692) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 12:01:21 PM Microsoft-Windows-WMI 5611 None The Windows Management Instrumentation service has detected an inconsistent system shutdown. Information 1/14/2013 12:01:21 PM ESENT 301 Logging/Recovery Windows (1692) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 12:01:21 PM ESENT 300 Logging/Recovery Windows (1692) Windows: The database engine is initiating recovery steps. Information 1/14/2013 12:01:21 PM ESENT 102 General Windows (1692) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 12:01:20 PM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 12:01:20 PM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 12:01:06 PM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 12:01:06 PM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 11:55:32 AM Windows Error Reporting 1001 None "Fault bucket 2563078971, type 5 Event Name: BEX64 Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: StackHash_1dc2 P5: 0.0.0.0 P6: 00000000 P7: 0000000000000000 P8: c0000005 P9: 0000000000000008 P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERB460.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_a8f2ce268d9b93da49cec4caf71acd33f87403e_0dfdcc33 Analysis symbol: Rechecking for solution: 0 Report Id: 92cd63f4-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Information 1/14/2013 11:55:30 AM Windows Error Reporting 1001 None "Fault bucket 3048658514, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: toshibaservicestation.exe P2: 2.2.4059.23056 P3: 4d55a0a0 P4: System.Windows.Forms P5: 2.0.0.0 P6: 4f682206 P7: 16e7 P8: 223 P9: System.ComponentModel.Win32 P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERBB52.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_toshibaservicest_b7a9d65bd04cbb319366c8301fb975d4ea8c8680_09d5c6e6 Analysis symbol: Rechecking for solution: 0 Report Id: 93e18393-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Error 1/14/2013 11:55:26 AM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0xc0000005 Fault offset: 0x0000000000000000 Faulting process id: 0xe68 Faulting application start time: 0x01cdf28050fb335a Faulting application path: C:\windows\Explorer.EXE Faulting module path: unknown Report Id: 92cd63f4-5e73-11e2-893d-c80aa98fda69" Information 1/14/2013 11:55:19 AM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WER7FAA.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0fc99903 Analysis symbol: Rechecking for solution: 0 Report Id: 8abffc48-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Error 1/14/2013 11:55:12 AM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xdf4 Faulting application start time: 0x01cdf280490a5c32 Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: 8abffc48-5e73-11e2-893d-c80aa98fda69" Information 1/14/2013 11:55:05 AM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WER4D06.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0c4964f9 Analysis symbol: Rechecking for solution: 0 Report Id: 8305e4c6-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Error 1/14/2013 11:54:59 AM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xc18 Faulting application start time: 0x01cdf280412c900c Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: 8305e4c6-5e73-11e2-893d-c80aa98fda69" Information 1/14/2013 11:54:52 AM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WER189E.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0ef1315c Analysis symbol: Rechecking for solution: 0 Report Id: 7b0463fc-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Error 1/14/2013 11:54:46 AM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xdfc Faulting application start time: 0x01cdf2803955e806 Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: 7b0463fc-5e73-11e2-893d-c80aa98fda69" Information 1/14/2013 11:54:39 AM Windows Error Reporting 1001 None "Fault bucket 34748340, type 4 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: Explorer.EXE P2: 6.1.7601.17567 P3: 4d672ee4 P4: stobject.dll P5: 6.1.7601.17514 P6: 4ce7c9c9 P7: c0000005 P8: 0000000000002c68 P9: P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERD4DB.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_Explorer.EXE_1f695eb3ff1c196ada5d1c5254ff7792988df5_0cc8fe0c Analysis symbol: Rechecking for solution: 0 Report Id: 70802fa8-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Information 1/14/2013 11:54:38 AM Windows Error Reporting 1001 None "Fault bucket 3371106675, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: mom.exe P2: 2.0.0.0 P3: 49ef8e68 P4: System P5: 2.0.0.0 P6: 503f053d P7: 165d P8: f9 P9: AMAG3AACMAWG2XAF344U21ACVE5PSTKL P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERD152.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mom.exe_b3e17a845ec1866852d35e2d1849b935608969a_0fd8faa3 Analysis symbol: Rechecking for solution: 0 Report Id: 70104efb-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Information 1/14/2013 11:54:38 AM Windows Error Reporting 1001 None "Fault bucket 3371106675, type 5 Event Name: CLR20r3 Response: Not available Cab Id: 0 Problem signature: P1: mom.exe P2: 2.0.0.0 P3: 49ef8e68 P4: System P5: 2.0.0.0 P6: 503f053d P7: 165d P8: f9 P9: AMAG3AACMAWG2XAF344U21ACVE5PSTKL P10: Attached files: C:\Users\Ada\AppData\Local\Temp\WERE4C2.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\Ada\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_mom.exe_b3e17a845ec1866852d35e2d1849b935608969a_0798faa3 Analysis symbol: Rechecking for solution: 0 Report Id: 73243675-5e73-11e2-893d-c80aa98fda69 Report Status: 0" Error 1/14/2013 11:54:28 AM Application Error 1000 (100) "Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4 Faulting module name: stobject.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c9c9 Exception code: 0xc0000005 Fault offset: 0x0000000000002c68 Faulting process id: 0xac8 Faulting application start time: 0x01cdf2802a3ca99b Faulting application path: C:\windows\Explorer.EXE Faulting module path: C:\windows\system32\stobject.dll Report Id: 70802fa8-5e73-11e2-893d-c80aa98fda69" Information 1/14/2013 11:54:17 AM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 11:54:14 AM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 11:54:11 AM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 11:54:14 AM Desktop Window Manager 9003 None The Desktop Window Manager was unable to start because a composited theme is not in use Information 1/14/2013 11:54:13 AM ESENT 302 Logging/Recovery Windows (2164) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 11:54:12 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 11:54:12 AM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 11:54:12 AM ESENT 301 Logging/Recovery Windows (2164) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 11:54:12 AM ESENT 300 Logging/Recovery Windows (2164) Windows: The database engine is initiating recovery steps. Information 1/14/2013 11:54:12 AM ESENT 102 General Windows (2164) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 11:54:11 AM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 11:53:55 AM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 11:53:55 AM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 11:49:58 AM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 11:49:55 AM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 11:49:53 AM ESENT 302 Logging/Recovery Windows (2100) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 11:49:52 AM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 11:49:51 AM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 11:49:51 AM ESENT 301 Logging/Recovery Windows (2100) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 11:49:51 AM ESENT 300 Logging/Recovery Windows (2100) Windows: The database engine is initiating recovery steps. Information 1/14/2013 11:49:51 AM ESENT 102 General Windows (2100) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 11:49:51 AM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 11:49:37 AM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 11:48:58 AM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 11:49:37 AM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 11:48:54 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 11:48:54 AM Desktop Window Manager 9009 None The Desktop Window Manager has exited with code (0x40010004) Information 1/14/2013 11:35:51 AM Microsoft-Windows-Security-SPP 903 None "The Software Protection service has stopped. " Information 1/14/2013 11:33:41 AM Microsoft-Windows-Backup 754 None The Block Level Backup Engine service has stopped. Information 1/14/2013 11:30:51 AM Microsoft-Windows-Security-SPP 902 None "The Software Protection service has started. 6.1.7601.17514" Information 1/14/2013 11:30:51 AM Microsoft-Windows-Security-SPP 1003 None "The description for Event ID 1003 from source Microsoft-Windows-Security-SPP cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: 55c92734-d682-4d71-983e-d6ec3f16059f 1: 01f5fc37-a99e-45c5-b65e-d762f3518ead, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 2e7d060d-4714-40f2-9896-1e4f15b612ad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 3b965dfc-31d9-4903-886f-873a0382776c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 586bc076-c93d-429a-afe5-a69fbc644e88, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 5e017a8a-f3f9-4167-b1bd-ba3e236a4d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: 5e35dc43-389b-47c5-b889-2088b06738cb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: 6a7d5d8a-92af-4e6a-af4b-8fddaec800e5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: 9ab82e0c-ffc9-4107-baa1-c65a8bd3ccc3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: 9f83d90f-a151-4665-ae69-30b3f63ec659, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: a63275f4-530c-48a7-b0d3-4f00d688d151, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: b8a4bb91-69b1-460d-93f8-40e0670af04a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: d2c04e90-c3dd-4260-b0f3-f845f5d27d64, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 13: e68b141f-4dfa-4387-b3b7-e65c4889216e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 14: ee4e1629-bcdc-4b42-a68f-b92e135f78d7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 15: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 16: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] The handle is invalid " Information 1/14/2013 11:30:50 AM Microsoft-Windows-Security-SPP 1066 None "Initialization status for service objects. C:\windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000 " Information 1/14/2013 11:30:49 AM Microsoft-Windows-Security-SPP 900 None "The Software Protection service is starting. " Information 1/14/2013 11:30:47 AM gupdate 0 None "The description for Event ID 0 from source gupdate cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: Service stopped " Information 1/14/2013 11:30:03 AM Service1 0 None Service started successfully. Information 1/14/2013 11:28:53 AM Windows Error Reporting 1001 None "Fault bucket , type 0 Event Name: APPCRASH Response: Not available Cab Id: 0 Problem signature: P1: TODDSrv.exe P2: 1.0.0.7 P3: 4a6e9c70 P4: ntdll.dll P5: 6.1.7601.17725 P6: 4ec4aa8e P7: c0000005 P8: 000000000009970a P9: P10: Attached files: C:\Windows\Temp\WER4E8C.tmp.appcompat.txt C:\Windows\Temp\WER4F67.tmp.WERInternalMetadata.xml C:\Windows\Temp\WER4F78.tmp.hdmp C:\Windows\Temp\WER50B1.tmp.mdmp These files may be available here: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_TODDSrv.exe_96cd17e5ec11dbed414beeb684a32593a546e091_cab_025950dd Analysis symbol: Rechecking for solution: 0 Report Id: da97f7db-5e6f-11e2-b404-c80aa98fda69 Report Status: 2" Information 1/14/2013 11:28:49 AM Windows Error Reporting 1001 None "The description for Event ID 1001 from source Windows Error Reporting cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer. If the event originated on another computer, the display information had to be saved with the event. The following information was included with the event: 0 APPCRASH Not available 0 TODDSrv.exe 1.0.0.7 4a6e9c70 ntdll.dll 6.1.7601.17725 4ec4aa8e c0000005 000000000009970a C:\Windows\Temp\WER4E8C.tmp.appcompat.txt C:\Windows\Temp\WER4F67.tmp.WERInternalMetadata.xml C:\Windows\Temp\WER4F78.tmp.hdmp C:\Windows\Temp\WER50B1.tmp.mdmp C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_TODDSrv.exe_96cd17e5ec11dbed414beeb684a32593a546e091_cab_025950dd 0 da97f7db-5e6f-11e2-b404-c80aa98fda69 6 The handle is invalid " Error 1/14/2013 11:28:48 AM Application Error 1000 (100) "Faulting application name: TODDSrv.exe, version: 1.0.0.7, time stamp: 0x4a6e9c70 Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x000000000009970a Faulting process id: 0x1cc Faulting application start time: 0x01cdf27c97ace4e1 Faulting application path: C:\Windows\system32\TODDSrv.exe Faulting module path: C:\windows\SYSTEM32\ntdll.dll Report Id: da97f7db-5e6f-11e2-b404-c80aa98fda69" Information 1/14/2013 11:28:46 AM Microsoft-Windows-Search 1003 Search service The Windows Search Service started. Information 1/14/2013 11:28:46 AM Desktop Window Manager 9003 None The Desktop Window Manager was unable to start because a composited theme is not in use Information 1/14/2013 11:28:45 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 11:28:45 AM Microsoft-Windows-Winlogon 4101 None Windows license validated. Information 1/14/2013 11:28:41 AM Microsoft-Windows-Backup 753 None The Block Level Backup Engine service has successfully started. Information 1/14/2013 11:28:42 AM ESENT 302 Logging/Recovery Windows (1124) Windows: The database engine has successfully completed recovery steps. Information 1/14/2013 11:28:42 AM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 11:28:42 AM ESENT 301 Logging/Recovery Windows (1124) Windows: The database engine has begun replaying logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Information 1/14/2013 11:28:42 AM ESENT 300 Logging/Recovery Windows (1124) Windows: The database engine is initiating recovery steps. Information 1/14/2013 11:28:42 AM ESENT 102 General Windows (1124) Windows: The database engine (6.01.7601.0000) started a new instance (0). Information 1/14/2013 11:28:41 AM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 11:28:33 AM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 11:28:33 AM Microsoft-Windows-EventSystem 4625 None The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog. Information 1/14/2013 7:48:28 AM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 7:48:27 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:48:27 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 7:48:27 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:48:27 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:48:27 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 7:48:26 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:43:07 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 1/14/2013 7:43:07 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:43:07 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:41:45 AM Microsoft-Windows-User Profiles Service 1531 None "The User Profile Service has started successfully. " Information 1/14/2013 7:41:50 AM Microsoft-Windows-WMI 5617 None Windows Management Instrumentation Service subsystems initialized successfully Information 1/14/2013 7:41:49 AM VSS 8211 None Volume Shadow Copy Service error: Writer with name WMI Writer and ID {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} attempted to subscribe in safe mode. Operation: Initializing Writer Context: Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0} Writer Name: WMI Writer Information 1/14/2013 7:41:45 AM Microsoft-Windows-WMI 5615 None Windows Management Instrumentation Service started sucessfully Information 1/14/2013 7:28:21 AM Microsoft-Windows-User Profiles Service 1532 None "The User Profile Service has stopped. " Information 1/14/2013 7:28:20 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:28:20 AM Desktop Window Manager 9009 None The Desktop Window Manager has exited with code (0x40010004) Information 1/14/2013 7:27:19 AM Desktop Window Manager 9003 None The Desktop Window Manager was unable to start because a composited theme is not in use Information 1/14/2013 7:27:19 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Information 1/14/2013 7:27:19 AM Microsoft-Windows-Winlogon 4101 None Windows license validated.