how to fix windows system event log error

Anonymous
2012-05-18T06:47:46+00:00

how to diagnose event log error..pls help.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2012-05-18T14:15:05+00:00

Here are some notes about Event Viewer Reports which may help. When you have a lot of errors you need to concentrate on system errors and warnings, even if it is applications that are giving you grief. Sorting system problems first can make resolving application problems easier. Note the time the computer is last booted and deal with those at the beginning of the boot first. Correcting the earlier errors can resolve later ones.

  1. Normally when an error occurs on your computer looking in Event Viewer should be your starting point for finding a solution. Most system related errors are logged and getting an exact copy of the relevant report is important. Unfortunately understanding the reports is not easy and most computer users need help with their interpretation. I have more to say later on interpretation.
  2. Event Viewer comprises three main Windows logs. These are Application, Security and System. For troubleshooting purposes System is by far the most important.
  3. To access the System log select Start, Control Panel, Administrative Tools, Event Viewer, from the list in the left side of the window select Windows Logs and System. Place the cursor on System, right click and select Filter Current Log. Check the box before Error and click on OK and you see only Error reports. Click on the Date and Time Column Header to sort. You may need to click a second time to see the latest Report at the top.
  4. A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. Click on the Copy button on the General tab to place a copy on your Clipboard and close Event Viewer. Now start your message and paste into the body of the message. Make sure this is the first paste after exiting from Event Viewer.
  5. There are three types of Report, being Information, Warning and Error reports. In most situations it is Error Reports that offer the best information but occasionally Warning Reports provide useful clues.
  6. All reports have date and time stamps and when troubleshooting it is important to concentrate on more recent reports. Study reports since the point when the computer was last booted and then check whether a similar report appeared in the previous session. If errors do not repeat investigation as to why they occurred is wasted effort.
  7. Within individual reports the more important information is Event ID and Source as these help when looking for help on the internet. The description is equally important and copying the exact text for use as the search criteria greatly helps getting better results when using Google. Do not paraphrase descriptions when asking others for help.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Oldest
  1. Anonymous
    2012-12-12T22:55:31+00:00

    After following the directions by Gerry I did as suggested and after the fact I still have error as follows: !

    Log Name:      System

    Source:        Service Control Manager

    Date:          12/12/2012 2:48:42 PM

    Event ID:      7036

    Task Category: None

    Level:         Information

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The Multimedia Class Scheduler service entered the stopped state.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />

    <EventID Qualifiers="16384">7036</EventID>

    <Version>0</Version>

    <Level>4</Level>

    <Task>0</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8080000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-12T22:48:42.906177700Z" />

    <EventRecordID>81266</EventRecordID>

    <Correlation />

    <Execution ProcessID="564" ThreadID="728" />

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data Name="param1">Multimedia Class Scheduler</Data>

    <Data Name="param2">stopped</Data>

    <Binary>4D004D004300530053002F0031000000</Binary>

    </EventData>

    </Event>

    Any help would be greatly appreciated! Thanks

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2012-12-12T22:58:12+00:00

    Here are the application system errors:

    Log Name:      Application

    Source:        Windows Error Reporting

    Date:          12/12/2012 2:56:05 PM

    Event ID:      1001

    Task Category: None

    Level:         Information

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    Fault bucket 3377269839, type 5

    Event Name: MpTelemetry

    Response: Not available

    Cab Id: 0

    Problem signature:

    P1: Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)

    P2: 4.1.522.0

    P3: TimeOut

    P4: 1.1.9002.0

    P5: fixed

    P6: 2 / 2049+

    P7: 5 / not boot

    P8:

    P9:

    P10:

    Attached files:

    These files may be available here:

    C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14

    Analysis symbol:

    Rechecking for solution: 0

    Report Id: 7549e683-4497-11e2-8bde-8f98b316eabc

    Report Status: 0

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Windows Error Reporting" />

    <EventID Qualifiers="0">1001</EventID>

    <Level>4</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-12T22:56:05.000000000Z" />

    <EventRecordID>24969</EventRecordID>

    <Channel>Application</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>3377269839</Data>

    <Data>5</Data>

    <Data>MpTelemetry</Data>

    <Data>Not available</Data>

    <Data>0</Data>

    <Data>Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094)</Data>

    <Data>4.1.522.0</Data>

    <Data>TimeOut</Data>

    <Data>1.1.9002.0</Data>

    <Data>fixed</Data>

    <Data>2 / 2049+</Data>

    <Data>5 / not boot</Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>

    </Data>

    <Data>C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_Microsoft Securi_92446d9393d18ffbccf3ab933b507c5568679_00b8bb14</Data>

    <Data>

    </Data>

    <Data>0</Data>

    <Data>7549e683-4497-11e2-8bde-8f98b316eabc</Data>

    <Data>0</Data>

    </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2012-12-13T09:45:34+00:00

    You need to post the logs as I want to look at the sequence of events leading up to the error and what is going on around the time of the error.

    Please upload copies of your System and Application logs from your Event Viewer to your Sky Drive and post a link here.

    To access the System log select Start, Control Panel, Administrative Tools, Event Viewer, from the list in the left side of the window select Windows Logs and System. Place the cursor on System, select Action from the Menu and Save All Events as and give the file a name. Do the same for the Applications log.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2012-12-13T23:15:19+00:00

    how to fix windows system event log error  Log Name:      System

    Source:        Microsoft-Windows-WindowsUpdateClient

    Date:          12/13/2012 3:12:27 PM

    Event ID:      19

    Task Category: Windows Update Agent

    Level:         Information

    Keywords:      Success,Installation

    User:          SYSTEM

    Computer:      Charles-PC

    Description:

    Installation Successful: Windows successfully installed the following update: Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.141.1799.0)

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="Microsoft-Windows-WindowsUpdateClient" Guid="{945A8954-C147-4ACD-923F-40C45405A658}" />

    <EventID>19</EventID>

    <Version>0</Version>

    <Level>4</Level>

    <Task>1</Task>

    <Opcode>13</Opcode>

    <Keywords>0x8000000000000018</Keywords>

    <TimeCreated SystemTime="2012-12-13T23:12:27.677191800Z" />

    <EventRecordID>81724</EventRecordID>

    <Correlation ActivityID="{85F4A364-C083-0001-ACFA-4464B9D8CD01}" />

    <Execution ProcessID="1140" ThreadID="3396" />

    <Channel>System</Channel>

    <Computer>Charles-PC</Computer>

    <Security UserID="S-1-5-18" />

    </System>

    <EventData>

    <Data Name="updateTitle">Definition Update for Microsoft Security Essentials - KB2310138 (Definition 1.141.1799.0)</Data>

    <Data Name="updateGuid">{3101E93C-04B5-4034-8A41-2C59CF1B985A}</Data>

    <Data Name="updateRevisionNumber">201</Data>

    </EventData>

    </Event>

    Log Name:      Application

    Source:        VSS

    Date:          12/13/2012 3:00:30 PM

    Event ID:      8224

    Task Category: None

    Level:         Information

    Keywords:      Classic

    User:          N/A

    Computer:      Charles-PC

    Description:

    The VSS service is shutting down due to idle timeout.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

    <System>

    <Provider Name="VSS" />

    <EventID Qualifiers="0">8224</EventID>

    <Level>4</Level>

    <Task>0</Task>

    <Keywords>0x80000000000000</Keywords>

    <TimeCreated SystemTime="2012-12-13T23:00:30.000000000Z" />

    <EventRecordID>24984</EventRecordID>

    <Channel>Application</Channel>

    <Computer>Charles-PC</Computer>

    <Security />

    </System>

    <EventData>

    <Data>

    </Data>

    <Binary>2D20436F64653A2020434F525356434330303030303737332D2043616C6C3A2020434F525356434330303030303735352D205049443A202030303030333430342D205449443A202030303030343333322D20434D443A2020433A5C57696E646F77735C73797374656D33325C76737376632E6578652020202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820</Binary>

    </EventData>

    </Event>

    I'm not sure how to send the full system or application files, even though I've copied them; it said -

    Please upload copies of your System and Application logs from your Event Viewer to your Sky Drive...where or how do I do this?

    Was this answer helpful?

    0 comments No comments