Critical LOg
Log Name: System
Source: Microsoft-Windows-Kernel-Power
Date: 3/10/2011 10:46:31 PM
Event ID: 41
Task Category: (63)
Level: Critical
Keywords: (2)
User: SYSTEM
Computer: oi-PC
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="
http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2011-03-11T06:46:31.435619200Z" />
<EventRecordID>177060</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>oi-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
ERROR log
</Event>
Log Name: System
Source: EventLog
Date: 3/10/2011 10:46:42 PM
Event ID: 6008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: oi-PC
Description:
The previous system shutdown at 10:44:59 PM on 3/10/2011 was unexpected.
Event Xml:
<Event xmlns="
http://schemas.micro.../events/event">
<System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-03-11T06:46:42.000000000Z" />
<EventRecordID>177053</EventRecordID>
<Channel>System</Channel>
<Computer>oi-PC</Computer>
<Security />
</System>
<EventData>
<Data>10:44:59 PM</Data>
<Data>3/10/2011</Data>
<Data>
</Data>
<Data>
</Data>
<Data>35783</Data>
<Data>
</Data>
<Data>
</Data>
<Binary>DB07030004000A0016002C003B00DF00DB07030005000B0006002C003B00DF00600900003C000000010000006009000000000000B00400000100000000000000</Binary>
</EventData>
Warning LOG
</Event>
Log Name: System
Source: Microsoft-Windows-Wininit
Date: 3/10/2011 10:46:48 PM
Event ID: 11
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: oi-PC
Description:
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications.
Event Xml:
<Event xmlns="
http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-Wininit" Guid="{206F6DEA-D3C5-4D10-BC72-989F03C8B84B}" />
<EventID>11</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2011-03-11T06:46:48.895649300Z" />
<EventRecordID>177097</EventRecordID>
<Correlation />
<Execution ProcessID="460" ThreadID="492" />
<Channel>System</Channel>
<Computer>oi-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="StringCount">1</Data>
<Data Name="String"> C:\Windows\system32\guard64.dll</Data>
</EventData>
</Event>