how to fix windows system event log error

Anonymous
2012-05-18T06:47:46+00:00

how to diagnose event log error..pls help.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2012-05-18T14:15:05+00:00

Here are some notes about Event Viewer Reports which may help. When you have a lot of errors you need to concentrate on system errors and warnings, even if it is applications that are giving you grief. Sorting system problems first can make resolving application problems easier. Note the time the computer is last booted and deal with those at the beginning of the boot first. Correcting the earlier errors can resolve later ones.

  1. Normally when an error occurs on your computer looking in Event Viewer should be your starting point for finding a solution. Most system related errors are logged and getting an exact copy of the relevant report is important. Unfortunately understanding the reports is not easy and most computer users need help with their interpretation. I have more to say later on interpretation.
  2. Event Viewer comprises three main Windows logs. These are Application, Security and System. For troubleshooting purposes System is by far the most important.
  3. To access the System log select Start, Control Panel, Administrative Tools, Event Viewer, from the list in the left side of the window select Windows Logs and System. Place the cursor on System, right click and select Filter Current Log. Check the box before Error and click on OK and you see only Error reports. Click on the Date and Time Column Header to sort. You may need to click a second time to see the latest Report at the top.
  4. A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. Click on the Copy button on the General tab to place a copy on your Clipboard and close Event Viewer. Now start your message and paste into the body of the message. Make sure this is the first paste after exiting from Event Viewer.
  5. There are three types of Report, being Information, Warning and Error reports. In most situations it is Error Reports that offer the best information but occasionally Warning Reports provide useful clues.
  6. All reports have date and time stamps and when troubleshooting it is important to concentrate on more recent reports. Study reports since the point when the computer was last booted and then check whether a similar report appeared in the previous session. If errors do not repeat investigation as to why they occurred is wasted effort.
  7. Within individual reports the more important information is Event ID and Source as these help when looking for help on the internet. The description is equally important and copying the exact text for use as the search criteria greatly helps getting better results when using Google. Do not paraphrase descriptions when asking others for help.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Newest
  1. Anonymous
    2012-12-15T23:42:39+00:00

    This is becoming tedious; I follow directions but this doesn't seem to help? I hope this is correct. I will continue to try! This same error goes on for days!

    Log Name:      System

    Source:        Service Control Manager

    Date:          12/15/2012 1:29:48 PM

    Event ID:      7001

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The Computer Browser service depends on the Server service which failed to start because of the following error:

    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />

    <EventID Qualifiers="49152">7001</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-15T21:29:48.480452000Z" />

    <EventRecordID>82104</EventRecordID>

    <Correlation />

    <Execution ProcessID="564" ThreadID="1536" />

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data Name="param1">Computer Browser</Data>

    <Data Name="param2">Server</Data>

    <Data Name="param3">%%1058</Data>

    </EventData>

    </Event>

    This is the second error:

    Log Name:      System

    Source:        Disk

    Date:          12/10/2012 9:22:25 AM

    Event ID:      11

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The driver detected a controller error on \Device\Harddisk2\DR2.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Disk" />

    <EventID Qualifiers="49156">11</EventID>

    <Level>2</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-10T17:22:25.065906000Z" />

    <EventRecordID>79422</EventRecordID>

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>\Device\Harddisk2\DR2</Data>

    <Binary>0E04680001000000000000000B0004C003010000000000000000000000082D0000000000000000009789260000000000FFFFFFFF060000004000000000000000FF0006120C000010000000003C0000000000000000A8F28B00000000D8C40D89000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>

    </EventData>

    </Event>

    This is the applications files:

    Log Name:      Application

    Source:        Windows Error Reporting

    Date:          12/12/2012 2:56:05 PM

    Event ID:      1001

    Task Category: None

    Level:         Information

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    Fault bucket 3377269839, type 5

    Event Name: MpTelemetry

    Response: Not available

    Cab Id: 0

    Problem signature:

    P1: Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)

    P2: 4.1.522.0

    P3: TimeOut

    P4: 1.1.9002.0

    P5: fixed

    P6: 2 / 2049+

    P7: 5 / not boot

    P8:

    P9:

    P10:

    Attached files:

    These files may be available here:

    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14

    Analysis symbol:

    Rechecking for solution: 0

    Report Id: 7549e683-4497-11e2-8bde-8f98b316eabc

    Report Status: 0

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Windows Error Reporting" />

    <EventID Qualifiers="0">1001</EventID>

    <Level>4</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-12T22:56:05.000000000Z" />

    <EventRecordID>24969</EventRecordID>

    <Channel>Application</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>3377269839</Data>

    <Data>5</Data>

    <Data>MpTelemetry</Data>

    <Data>Not available</Data>

    <Data>0</Data>

    <Data>Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)</Data>

    <Data>4.1.522.0</Data>

    <Data>TimeOut</Data>

    <Data>1.1.9002.0</Data>

    <Data>fixed</Data>

    <Data>2 / 2049+</Data>

    <Data>5 / not boot</Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14</Data>

    <Data>

    </Data>

    <Data>0</Data>

    <Data>7549e683-4497-11e2-8bde-8f98b316eabc</Data>

    <Data>0</Data>

    </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2012-12-15T21:39:58+00:00

    This is becoming tedious; I follow directions but this doesn't seem to help? I hope this is correct. I will continue to try! This same error goes on for days!

    Log Name:      System

    Source:        Service Control Manager

    Date:          12/15/2012 1:29:48 PM

    Event ID:      7001

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The Computer Browser service depends on the Server service which failed to start because of the following error:

    The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />

    <EventID Qualifiers="49152">7001</EventID>

    <Version>0</Version>

    <Level>2</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-15T21:29:48.480452000Z" />

    <EventRecordID>82104</EventRecordID>

    <Correlation />

    <Execution ProcessID="564" ThreadID="1536" />

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data Name="param1">Computer Browser</Data>

    <Data Name="param2">Server</Data>

    <Data Name="param3">%%1058</Data>

    </EventData>

    </Event>

    This is the second error:

    Log Name:      System

    Source:        Disk

    Date:          12/10/2012 9:22:25 AM

    Event ID:      11

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The driver detected a controller error on \Device\Harddisk2\DR2.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Disk" />

    <EventID Qualifiers="49156">11</EventID>

    <Level>2</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-10T17:22:25.065906000Z" />

    <EventRecordID>79422</EventRecordID>

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>\Device\Harddisk2\DR2</Data>

    <Binary>0E04680001000000000000000B0004C003010000000000000000000000082D0000000000000000009789260000000000FFFFFFFF060000004000000000000000FF0006120C000010000000003C0000000000000000A8F28B00000000D8C40D89000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>

    </EventData>

    </Event>

    This is the applications files:

    Log Name:      Application

    Source:        Windows Error Reporting

    Date:          12/12/2012 2:56:05 PM

    Event ID:      1001

    Task Category: None

    Level:         Information

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    Fault bucket 3377269839, type 5

    Event Name: MpTelemetry

    Response: Not available

    Cab Id: 0

    Problem signature:

    P1: Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)

    P2: 4.1.522.0

    P3: TimeOut

    P4: 1.1.9002.0

    P5: fixed

    P6: 2 / 2049+

    P7: 5 / not boot

    P8:

    P9:

    P10:

    Attached files:

    These files may be available here:

    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14

    Analysis symbol:

    Rechecking for solution: 0

    Report Id: 7549e683-4497-11e2-8bde-8f98b316eabc

    Report Status: 0

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Windows Error Reporting" />

    <EventID Qualifiers="0">1001</EventID>

    <Level>4</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-12T22:56:05.000000000Z" />

    <EventRecordID>24969</EventRecordID>

    <Channel>Application</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>3377269839</Data>

    <Data>5</Data>

    <Data>MpTelemetry</Data>

    <Data>Not available</Data>

    <Data>0</Data>

    <Data>Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)</Data>

    <Data>4.1.522.0</Data>

    <Data>TimeOut</Data>

    <Data>1.1.9002.0</Data>

    <Data>fixed</Data>

    <Data>2 / 2049+</Data>

    <Data>5 / not boot</Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14</Data>

    <Data>

    </Data>

    <Data>0</Data>

    <Data>7549e683-4497-11e2-8bde-8f98b316eabc</Data>

    <Data>0</Data>

    </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2012-12-15T06:14:40+00:00

    Unfortunately your link takes me to an empty folder!

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2012-12-15T02:57:43+00:00

    https://skydrive.live.com/?cid=8E9886F3864E2425

    Here are files from skydrive. Thanks

    Was this answer helpful?

    0 comments No comments