how to fix windows system event log error

Anonymous
2012-05-18T06:47:46+00:00

how to diagnose event log error..pls help.

Windows for home | Previous Windows versions | Windows update

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2012-05-18T14:15:05+00:00

Here are some notes about Event Viewer Reports which may help. When you have a lot of errors you need to concentrate on system errors and warnings, even if it is applications that are giving you grief. Sorting system problems first can make resolving application problems easier. Note the time the computer is last booted and deal with those at the beginning of the boot first. Correcting the earlier errors can resolve later ones.

  1. Normally when an error occurs on your computer looking in Event Viewer should be your starting point for finding a solution. Most system related errors are logged and getting an exact copy of the relevant report is important. Unfortunately understanding the reports is not easy and most computer users need help with their interpretation. I have more to say later on interpretation.
  2. Event Viewer comprises three main Windows logs. These are Application, Security and System. For troubleshooting purposes System is by far the most important.
  3. To access the System log select Start, Control Panel, Administrative Tools, Event Viewer, from the list in the left side of the window select Windows Logs and System. Place the cursor on System, right click and select Filter Current Log. Check the box before Error and click on OK and you see only Error reports. Click on the Date and Time Column Header to sort. You may need to click a second time to see the latest Report at the top.
  4. A tip for posting copies of Error Reports! Run Event Viewer and double click on the error you want to copy. Click on the Copy button on the General tab to place a copy on your Clipboard and close Event Viewer. Now start your message and paste into the body of the message. Make sure this is the first paste after exiting from Event Viewer.
  5. There are three types of Report, being Information, Warning and Error reports. In most situations it is Error Reports that offer the best information but occasionally Warning Reports provide useful clues.
  6. All reports have date and time stamps and when troubleshooting it is important to concentrate on more recent reports. Study reports since the point when the computer was last booted and then check whether a similar report appeared in the previous session. If errors do not repeat investigation as to why they occurred is wasted effort.
  7. Within individual reports the more important information is Event ID and Source as these help when looking for help on the internet. The description is equally important and copying the exact text for use as the search criteria greatly helps getting better results when using Google. Do not paraphrase descriptions when asking others for help.

Was this answer helpful?

100+ people found this answer helpful.
0 comments No comments

47 additional answers

Sort by: Oldest
  1. Anonymous
    2012-12-24T23:09:06+00:00

    If you want me to comment  upload your system and application logs to your Sky Drive, share with everylone and post a link to your Sky Drive here.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2012-12-24T23:50:03+00:00

    Like I said, there's nothing to see in those logs, with the sole exception of the TimeOut message from Antimalware. Believe me, I know, and understand, my event logs myself. For example, I have done a one-to-one comparison of the messages coming from my system running on an image from a week ago (that did not have this issue), and the system the way it is now (with MSE timing out). There is no difference, neither in the content nor in the sequence of the messages, with the sole exception of the TimeOut message (and, of course, the sequence pausing for roughly four minutes on the system running off the newer system image).

    So, what I am looking for is someone faimilar enough with MSE itself to either be able to help me diagnose the issue, or have suggestions for possible causes immediately. Lacking that, I have uninstalled MSE, and the system starts up and runs perfectly. It's not like MSE has ever done anything for me anyway...

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-10-03T08:50:27+00:00

    How do I fix this error:

    Log Name:      System

    Source:        Microsoft-Windows-DistributedCOM

    Date:          10/2/2013 12:32:20 AM

    Event ID:      10016

    Task Category: None

    Level:         Error

    Keywords:      Classic

    User:          user

    Computer:      mine

    Description:

    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID

    {B77C4C36-0154-4C52-AB49-FAA03837E47F}

     and APPID

    {EA022610-0748-4C24-B229-6C507EBDFDBB}

     to the user user\mine SID (S-1-5-21-530721808-2163332003-611588842-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

    Event Xml:

    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

      <System>

        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />

        <EventID Qualifiers="0">10016</EventID>

        <Version>0</Version>

        <Level>2</Level>

        <Task>0</Task>

        <Opcode>0</Opcode>

        <Keywords>0x8080000000000000</Keywords>

        <TimeCreated SystemTime="2013-10-02T04:32:20.938607100Z" />

        <EventRecordID>7384</EventRecordID>

        <Correlation />

        <Execution ProcessID="972" ThreadID="32" />

        <Channel>System</Channel>

        <Computer>user</Computer>

        <Security UserID="S-1-5-21-530721808-2163332003-611588842-1001" />

      </System>

      <EventData>

        <Data Name="param1">application-specific</Data>

        <Data Name="param2">Local</Data>

        <Data Name="param3">Activation</Data>

        <Data Name="param4">{B77C4C36-0154-4C52-AB49-FAA03837E47F}</Data>

        <Data Name="param5">{EA022610-0748-4C24-B229-6C507EBDFDBB}</Data>

        <Data Name="param6">user</Data>

        <Data Name="param7">mine</Data>

        <Data Name="param8">S-1-5-21-530721808-2163332003-611588842-1001</Data>

        <Data Name="param9">LocalHost (Using LRPC)</Data>

        <Data Name="param10">Unavailable</Data>

        <Data Name="param11">Unavailable</Data>

      </EventData>

    </Event>

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2013-10-03T11:29:49+00:00

    Was this answer helpful?

    0 comments No comments