作者Gwent (昆特)
看板Windows
标题[问题] windows发生严重问题
时间Tue Dec 12 21:08:18 2017
今天 我打开电脑
却跳出 Windows 发生严重问题, 并且在一分钟内重新启动 的视窗
我查看了事件检视器後
发现了几种错误
记录档名称: System
来源: Service Control Manager
日期: 2017/12/12 下午 08:18:56
事件识别码: 7001
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
Computer Browser 服务依存的 Server 服务因为发生下列错误而无法启动:
相依性服务或群组无法启动。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager"
Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service
Control Manager" />
<EventID Qualifiers="49152">7001</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:18:56.504328900Z" />
<EventRecordID>236568</EventRecordID>
<Correlation />
<Execution ProcessID="564" ThreadID="2816" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">Computer Browser</Data>
<Data Name="param2">Server</Data>
<Data Name="param3">%%1068</Data>
</EventData>
</Event>
记录档名称: System
来源: Microsoft-Windows-DistributedCOM
日期: 2017/12/12 下午 08:18:17
事件识别码: 10005
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
DCOM 为了执行伺服器:
{4991D34B-80A1-4291-83B6-3328366B9097},而尝试启动含有引数 "" 的服务 BITS 时,
遇到错误 "1068"
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM"
Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="49152">10005</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:18:17.000000000Z" />
<EventRecordID>236559</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">1068</Data>
<Data Name="param2">BITS</Data>
<Data Name="param3">
</Data>
<Data Name="param4">{4991D34B-80A1-4291-83B6-3328366B9097}</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-WMI
日期: 2017/12/12 下午 08:13:28
事件识别码: 10
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60
WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage
> 99" could not be reactivated in namespace "//./root/CIMV2" because of error
0x80041003. Events cannot be delivered through this filter until the problem
is corrected.
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WMI"
Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" EventSourceName="WinMgmt" />
<EventID Qualifiers="49152">10</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:13:28.000000000Z" />
<EventRecordID>75785</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>//./root/CIMV2</Data>
<Data>SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE
TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage >
99</Data>
<Data>0x80041003</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-Winlogon
日期: 2017/12/12 下午 08:11:55
事件识别码: 6000
工作类别: 无
等级: 警告
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
winlogon 通知订阅者 <GPClient> 无法处理通知事件。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Winlogon"
Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
<EventID Qualifiers="32768">6000</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:55.000000000Z" />
<EventRecordID>75783</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>GPClient</Data>
<Binary>D9060000</Binary>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-Winlogon
日期: 2017/12/12 下午 08:11:55
事件识别码: 4103
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
Windows 授权启用失败。错误 0x00000000。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Winlogon"
Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Winlogon" />
<EventID Qualifiers="49152">4103</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:55.000000000Z" />
<EventRecordID>75781</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>0x00000000</Data>
<Data>0x00000001</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-Security-SPP
日期: 2017/12/12 下午 08:11:55
事件识别码: 8198
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
授权启用 (slui.exe) 失败,错误码如下:
0x8007043C
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-SPP"
Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software
Protection Platform Service" />
<EventID Qualifiers="49152">8198</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:55.000000000Z" />
<EventRecordID>75780</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>0x8007043C</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-Winlogon
日期: 2017/12/12 下午 08:11:54
事件识别码: 4105
工作类别: 无
等级: 警告
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
Windows 目前在通知期间。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Winlogon"
Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Winlogon" />
<EventID Qualifiers="32768">4105</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:54.000000000Z" />
<EventRecordID>75779</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>0x00000000</Data>
<Data>0x00000000</Data>
</EventData>
</Event>
记录档名称: System
来源: Service Control Manager
日期: 2017/12/12 下午 08:11:48
事件识别码: 7026
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
下列开机启动或系统启动驱动程式无法载入:
avipbb
avkmgr
discache
spldr
VBoxDrv
VBoxUSBMon
Wanarpv6
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager"
Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service
Control Manager" />
<EventID Qualifiers="49152">7026</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:48.500833400Z" />
<EventRecordID>236530</EventRecordID>
<Correlation />
<Execution ProcessID="564" ThreadID="568" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">
avipbb
avkmgr
discache
spldr
VBoxDrv
VBoxUSBMon
Wanarpv6</Data>
</EventData>
</Event>
记录档名称: Security
来源: Microsoft-Windows-Eventlog
日期: 2017/12/12 下午 08:11:47
事件识别码: 1101
工作类别: 事件正在处理
等级: 错误
关键字: 稽核成功
使用者: 不适用
电脑: user-PC
描述:
传输已丢弃稽核事件。0
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Eventlog"
Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
<EventID>1101</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>101</Task>
<Opcode>0</Opcode>
<Keywords>0x4020000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:47.783232200Z" />
<EventRecordID>54334</EventRecordID>
<Correlation />
<Execution ProcessID="852" ThreadID="1140" />
<Channel>Security</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<UserData>
<AuditEventsDropped
xmlns:auto-ns3="
http://schemas.microsoft.com/win/2004/08/events"
xmlns="
http://manifests.microsoft.com/win/2004/08/windows/eventlog">
<Reason>0</Reason>
</AuditEventsDropped>
</UserData>
</Event>
记录档名称: System
来源: Microsoft-Windows-Kernel-Power
日期: 2017/12/12 下午 08:11:32
事件识别码: 41
工作类别: (63)
等级: 重大
关键字: (2)
使用者: SYSTEM
电脑: user-PC
描述:
系统已重新开机,但未先正常关机。若系统停止回应、当机或电力意外中断,就可能会造
成此错误。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Kernel-Power"
Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>2</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000002</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:32.651205600Z" />
<EventRecordID>236503</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">false</Data>
<Data Name="PowerButtonTimestamp">0</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-Winlogon
日期: 2017/12/12 下午 08:11:55
事件识别码: 6000
工作类别: 无
等级: 警告
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
winlogon 通知订阅者 <GPClient> 无法处理通知事件。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Winlogon"
Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
<EventID Qualifiers="32768">6000</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:55.000000000Z" />
<EventRecordID>75783</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>GPClient</Data>
<Binary>D9060000</Binary>
</EventData>
</Event>
记录档名称: System
来源: EventLog
日期: 2017/12/12 下午 08:11:42
事件识别码: 6008
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
017/2/2 上 下午 08:10:13 的系统上次发生意外的关机。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T12:11:42.000000000Z" />
<EventRecordID>236499</EventRecordID>
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>下午 08:10:13</Data>
<Data>017/2/2</Data>
<Data>
</Data>
<Data>
</Data>
<Data>618</Data>
<Data>
</Data>
<Data>
</Data>
<Binary>E1070C0002000C0014000A000D00E303E1070C0002000C000C000A000D00E303600900003C000000010000006009000000000000B00400000100000000000000</Binary>
</EventData>
</Event>
记录档名称: System
来源: Service Control Manager
日期: 2017/12/12 下午 07:54:33
事件识别码: 7000
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
rtop 服务无法启动,因为下列错误:
系统找不到指定的档案。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager"
Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service
Control Manager" />
<EventID Qualifiers="49152">7000</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T11:54:33.345303600Z" />
<EventRecordID>236383</EventRecordID>
<Correlation />
<Execution ProcessID="748" ThreadID="752" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">rtop</Data>
<Data Name="param2">%%2</Data>
</EventData>
</Event>
记录档名称: System
来源: Service Control Manager
日期: 2017/12/12 下午 07:54:33
事件识别码: 7009
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
等候 Keepvid Application Framework Service 服务连线时发生逾时 (30000 毫秒)。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Service Control Manager"
Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service
Control Manager" />
<EventID Qualifiers="49152">7009</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T11:54:33.173703300Z" />
<EventRecordID>236378</EventRecordID>
<Correlation />
<Execution ProcessID="748" ThreadID="752" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="param1">30000</Data>
<Data Name="param2">Keepvid Application Framework Service</Data>
</EventData>
</Event>
记录档名称: Application
来源: Application Error
日期: 2017/12/12 下午 07:52:07
事件识别码: 1000
工作类别: (100)
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
失败的应用程式名称: services.exe,版本: 6.1.7601.18829,时间戳记: 0x552b23d3
失败的模组名称: KERNELBASE.dll,版本: 6.1.7601.23915,时间戳记: 0x59b94f2a
例外状况码: 0xe06d7363
错误位移: 0x000000000001a06d
失败的处理程序识别码: 0x2ec
失败的应用程式开始时间: 0x01d3733f76fae45b
失败的应用程式路径: C:\Windows\system32\services.exe
失败的模组路径: C:\Windows\system32\KERNELBASE.dll
报告识别码: e0709f26-df32-11e7-af01-00acdc1c6837
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Level>2</Level>
<Task>100</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-12T11:52:07.000000000Z" />
<EventRecordID>75721</EventRecordID>
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>services.exe</Data>
<Data>6.1.7601.18829</Data>
<Data>552b23d3</Data>
<Data>KERNELBASE.dll</Data>
<Data>6.1.7601.23915</Data>
<Data>59b94f2a</Data>
<Data>e06d7363</Data>
<Data>000000000001a06d</Data>
<Data>2ec</Data>
<Data>01d3733f76fae45b</Data>
<Data>C:\Windows\system32\services.exe</Data>
<Data>C:\Windows\system32\KERNELBASE.dll</Data>
<Data>e0709f26-df32-11e7-af01-00acdc1c6837</Data>
</EventData>
</Event>
记录档名称: System
来源: Microsoft-Windows-WHEA-Logger
日期: 2017/12/11 下午 08:21:10
事件识别码: 19
工作类别: 无
等级: 警告
关键字:
使用者: LOCAL SERVICE
电脑: user-PC
描述:
发生已修正的硬体错误。
报告元件: 处理器核心
错误来源: 已修正电脑检查
错误类型: 内部同位检查错误
处理器识别码: 1
此项目的详细资料检视包含详细资讯。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WHEA-Logger"
Guid="{C26C4F3C-3F66-4E99-8F8A-39405CFED220}" />
<EventID>19</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2017-12-11T12:21:10.214769100Z" />
<EventRecordID>234990</EventRecordID>
<Correlation ActivityID="{894EC5AD-6E7A-4237-BE91-6CAADA1655D3}" />
<Execution ProcessID="1760" ThreadID="4500" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-19" />
</System>
<EventData>
<Data Name="ErrorSource">1</Data>
<Data Name="ApicId">1</Data>
<Data Name="MCABank">0</Data>
<Data Name="MciStat">0x90000040000f0005</Data>
<Data Name="MciAddr">0x0</Data>
<Data Name="MciMisc">0x0</Data>
<Data Name="ErrorType">12</Data>
<Data Name="TransactionType">256</Data>
<Data Name="Participation">256</Data>
<Data Name="RequestType">256</Data>
<Data Name="MemorIO">256</Data>
<Data Name="MemHierarchyLvl">256</Data>
<Data Name="Timeout">256</Data>
<Data Name="OperationType">256</Data>
<Data Name="Channel">256</Data>
<Data Name="Length">864</Data>
<Data
Name="RawData">435045521002FFFFFFFF030002000000020000006003000009150C000B0C11140000000000000000000000000000000000000000000000000000000000000000BDC407CF89B7184EB3C41F732CB57131B18BCE2DD7BD0E45B9AD9CF4EBD4F890C8831E92B170D30100000000000000000000000000000000000000000000000058010000C00000000102000001000000ADCC7698B447DB4BB65E16F193C4F3DB0000000000000000000000000000000002000000000000000000000000000000000000000000000018020000400000000102000000000000B0A03EDC44A19747B95B53FA242B6E1D0000000000000000000000000000000
002000000000000000000000000000000000000000000000058020000080100000102000000000000011D1E8AF94257459C33565E5CC3F7E80000000000000000000000000000000002000000000000000000000000000000000000000000000057010000000000000002080000000000C30603000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000
000000000000000000000000000000000000000000000000000000000000000000003000000000000000100000000000000C306030000081001FFFBFA7FFFFBEBBF00000000000000000000000000000000000000000000000000000000000000000100000001000000DA9DED867A72D30101000000000000000000000000000000000000000000000005000F0040000090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
</EventData>
</Event>
记录档名称: System
来源: volsnap
日期: 2017/12/11 下午 07:51:24
事件识别码: 36
工作类别: 无
等级: 错误
关键字: 传统
使用者: 不适用
电脑: user-PC
描述:
因为使用者规定了限制所以阴影复制储存区无法扩充,磁碟区 C: 的阴影复制被中止。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="volsnap" />
<EventID Qualifiers="49158">36</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2017-12-11T11:51:24.340266100Z" />
<EventRecordID>234981</EventRecordID>
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security />
</System>
<EventData>
<Data>\Device\HarddiskVolumeShadowCopy2</Data>
<Data>C:</Data>
<Binary>000000000200300000000000240006C0020000000000000001000000000000000000000000000000</Binary>
</EventData>
</Event>
记录档名称: System
来源: Microsoft-Windows-DNS-Client
日期: 2017/12/11 下午 05:07:03
事件识别码: 1014
工作类别: 无
等级: 警告
关键字:
使用者: NETWORK SERVICE
电脑: user-PC
描述:
设定的 DNS 伺服器没有回应,名称 wpad.domain.name 的名称解析逾时。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DNS-Client"
Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
<EventID>1014</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x4000000000000000</Keywords>
<TimeCreated SystemTime="2017-12-11T09:07:03.434995100Z" />
<EventRecordID>234943</EventRecordID>
<Correlation />
<Execution ProcessID="1408" ThreadID="4128" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-20" />
</System>
<EventData>
<Data Name="QueryName">wpad.domain.name</Data>
<Data Name="AddressLength">16</Data>
<Data Name="Address">02000035C0A864010000000000000000</Data>
</EventData>
</Event>
记录档名称: System
来源: Microsoft-Windows-Time-Service
日期: 2017/12/11 上午 08:06:07
事件识别码: 134
工作类别: 无
等级: 警告
关键字:
使用者: LOCAL SERVICE
电脑: user-PC
描述:
因为在 '' 上发生 DNS 解析错误,所以 NtpClient 无法将手动对等设定成时间来源。
NtpClient 会在 3473457 分钟後再试一次,并在此後将重试间隔加倍。错误为: 要求的
名称正确,但找不到所要求类型的资料。 (0x80072AFC)。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Time-Service"
Guid="{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}" />
<EventID>134</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2017-12-11T00:06:07.436207200Z" />
<EventRecordID>234845</EventRecordID>
<Correlation />
<Execution ProcessID="1100" ThreadID="4984" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-19" />
</System>
<EventData Name="TMP_EVENT_MANUAL_PEER_DNS_ERROR">
<Data Name="ErrorMessage">要求的名称正确,但找不到所要求类型的资料。
(0x80072AFC)</Data>
<Data Name="RetryMinutes">3473457</Data>
<Data Name="DomainPeer">
</Data>
</EventData>
</Event>
记录档名称: Application
来源: Microsoft-Windows-User Profiles Service
日期: 2017/12/10 下午 11:48:46
事件识别码: 1530
工作类别: 无
等级: 警告
关键字:
使用者: SYSTEM
电脑: user-PC
描述:
Windows 侦测到您的登录档仍由其他应用程式或服务使用中。现在会解除载入该档案。之
後,占用您登录档的应用程式或服务可能无法正常运作。
详细资料 -
5 user registry handles leaked from
\Registry\User\S-1-5-21-3754324190-1126028086-2999850407-1001:
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Connections
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Avira\Safe
Shopping\Config
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 1976 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Antivirus\avguard.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service"
Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2017-12-10T15:48:46.072145500Z" />
<EventRecordID>75323</EventRecordID>
<Correlation />
<Execution ProcessID="1220" ThreadID="7832" />
<Channel>Application</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">5 user registry handles leaked from
\Registry\User\S-1-5-21-3754324190-1126028086-2999850407-1001:
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\Connections
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Avira\Safe
Shopping\Config
Process 2260 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 1976 (\Device\HarddiskVolume2\Program Files
(x86)\Avira\Antivirus\avguard.exe) has opened key
\REGISTRY\USER\S-1-5-21-3754324190-1126028086-2999850407-1001\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon
</Data>
</EventData>
</Event>
记录档名称: System
来源: Microsoft-Windows-Time-Service
日期: 2017/12/10 上午 11:26:17
事件识别码: 134
工作类别: 无
等级: 警告
关键字:
使用者: LOCAL SERVICE
电脑: user-PC
描述:
因为在 '' 上发生 DNS 解析错误,所以 NtpClient 无法将手动对等设定成时间来源。
NtpClient 会在 3473457 分钟後再试一次,并在此後将重试间隔加倍。错误为: 要求的
名称正确,但找不到所要求类型的资料。 (0x80072AFC)。
事件 Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Time-Service"
Guid="{06EDCFEB-0FD0-4E53-ACCA-A6F8BBF81BCB}" />
<EventID>134</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2017-12-10T03:26:17.177554400Z" />
<EventRecordID>234712</EventRecordID>
<Correlation />
<Execution ProcessID="1100" ThreadID="836" />
<Channel>System</Channel>
<Computer>user-PC</Computer>
<Security UserID="S-1-5-19" />
</System>
<EventData Name="TMP_EVENT_MANUAL_PEER_DNS_ERROR">
<Data Name="ErrorMessage">要求的名称正确,但找不到所要求类型的资料。
(0x80072AFC)</Data>
<Data Name="RetryMinutes">3473457</Data>
<Data Name="DomainPeer">
</Data>
</EventData>
</Event>
请问可以帮我看一看是什麽问题吗 抱歉文有点长
想说还是附上详细资料比较好
不过能看到这里 我也很感激 还满担心会因为文太长被直接略过
先谢谢大家了
--
※ 发信站: 批踢踢实业坊(ptt.cc), 来自: 182.235.170.230
※ 文章网址: https://webptt.com/cn.aspx?n=bbs/Windows/M.1513084102.A.ECA.html
1F:→ vivian90369: 有更新系统?有试着重灌电脑? 12/12 21:10
2F:→ Gwent: 目前还没尝试重灌电脑 想说有没有希望不用重灌就修好 12/12 21:27