Eugene3D
1 Copper

The processor reduced performance after computer comes back from sleep.

My Dell studio XPS 1645 with Windows 7 64 bit gets in the strange state after it comes back from sleep. The system performance gets reduced, Intel Turbo Boost stops working as the blue bar never appears on the icon, the Intel(R) Processor ID Utility shows significantly reduced rates, and these numbers may wary time to time:

CPU Speed: Reported 1.19 GHz/ Expected 1.60 GHZ

Intel(R) QPI: Reported 2.39 GT/s / Expected 4.26 GT/s

IMC Speed: Reported 747 MHZ/ Expected 133 MHZ

Event Viewer gets full of messages while the overall system performance is noticeably reduced:

"The speed of processor ( all from 0 to 7) in group 0 is being limited by system firmware. The processor has been in this reduced performance state for 71 seconds since the last report.

Log name: System

Source: Kernel-Processor-Power

Event ID:  37

Level: Warning

User: System

Processor performance comes back to normal after reboot, though I use sleep on this laptop often so it gets decreased again eventually.

All drivers, BIOS, and Windows and Anivirus are UP TO DATE.

Dell support, give an answer what the hell is this? 

0 Kudos
2 Replies
DELL-Terry B
5 Tungsten

Re: The processor reduced performance after computer comes back from sleep.

Eugene

Since the system performs correctly after starting the notebook, it is unlikely that the system has defective hardware.

I do suggest running diagnostics just to make sure.  Start the system tapping F12 and choose diagnostics.  Allow the test to complete and please reply back here with any errors.

If the diagnostics doesn't find a problem, then there is likely a program or utility running in the background that could be affecting performance.  As a test I am going to suggest killing everything using msconfig.  To start msconfig click on start, search and type msconfig.  Click the services tab and check hide all Microsoft services, then click disable all. Click the start up tab and click disable all and then OK and allow the system to restart.  Once the system restarts place the notebook to sleep and then resume it from sleep.  Do you notice the same behavior?  

Other things to look out for is power management settings, the system could be throttling back to save power.  Click on start, control panel power options and check what the settings are.  As a test select high performance and see if the problem continues.

Since you don't notice the slower performance when starting the notebook up, the notebook is likely fine. If you aren't concerned with battery power then keep the system on high performance.  If it turns out to be software related, then you can use msconfig and process of elimination to determine what specific programs are slowing the system down.  When finished with msconfig please return it to normal start up.

If you can't find out what specific program is causing the problem and don't want to try something like reinstalling Windows to try to solve this, you can simply shut the system down instead of placing the system to sleep. It certainly isn't perfect but keeps you from having to spend the time on re imaging the system.

I hope that this helps

TB

Specialize in Laptops, Mobile Devices
#IWork4Dell

0 Kudos
makawiss
1 Copper

RE: The processor reduced performance after computer comes back from sleep.

Top of the day to you B, I need your expert advice on a kernel security check failure message on my new dell inspiron. I have copied from the events log the error messages:

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          8/3/2016 7:17:33 AM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (70368744177664),(2)
User:          SYSTEM
Computer:      ALIOU
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
    <EventID>41</EventID>
    <Version>3</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000002</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:17:33.627401400Z" />
    <EventRecordID>4002</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">313</Data>
    <Data Name="BugcheckParameter1">0x21</Data>
    <Data Name="BugcheckParameter2">0xffffd0014585c420</Data>
    <Data Name="BugcheckParameter3">0xffffd0014585c378</Data>
    <Data Name="BugcheckParameter4">0x0</Data>
    <Data Name="SleepInProgress">0</Data>
    <Data Name="PowerButtonTimestamp">0</Data>
    <Data Name="BootAppStatus">0</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          2/3/2016 9:36:29 PM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (70368744177664),(2)
User:          SYSTEM
Computer:      Mackie
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
    <EventID>41</EventID>
    <Version>3</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000002</Keywords>
    <TimeCreated SystemTime="2016-03-03T02:36:29.677638400Z" />
    <EventRecordID>2608</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">0</Data>
    <Data Name="BugcheckParameter1">0x0</Data>
    <Data Name="BugcheckParameter2">0x0</Data>
    <Data Name="BugcheckParameter3">0x0</Data>
    <Data Name="BugcheckParameter4">0x0</Data>
    <Data Name="SleepInProgress">0</Data>
    <Data Name="PowerButtonTimestamp">0</Data>
    <Data Name="BootAppStatus">0</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          2/3/2016 5:16:09 PM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (70368744177664),(2)
User:          SYSTEM
Computer:      Mackie
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
    <EventID>41</EventID>
    <Version>3</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000002</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:16:09.277665400Z" />
    <EventRecordID>1936</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">313</Data>
    <Data Name="BugcheckParameter1">0x21</Data>
    <Data Name="BugcheckParameter2">0xffffd000a34bb420</Data>
    <Data Name="BugcheckParameter3">0xffffd000a34bb378</Data>
    <Data Name="BugcheckParameter4">0x0</Data>
    <Data Name="SleepInProgress">0</Data>
    <Data Name="PowerButtonTimestamp">0</Data>
    <Data Name="BootAppStatus">0</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-Power
Date:          26/2/2016 6:37:48 PM
Event ID:      41
Task Category: (63)
Level:         Critical
Keywords:      (70368744177664),(2)
User:          SYSTEM
Computer:      Mackie
Description:
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
    <EventID>41</EventID>
    <Version>3</Version>
    <Level>1</Level>
    <Task>63</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000400000000002</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:37:48.421631000Z" />
    <EventRecordID>1120</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="BugcheckCode">0</Data>
    <Data Name="BugcheckParameter1">0x0</Data>
    <Data Name="BugcheckParameter2">0x0</Data>
    <Data Name="BugcheckParameter3">0x0</Data>
    <Data Name="BugcheckParameter4">0x0</Data>
    <Data Name="SleepInProgress">0</Data>
    <Data Name="PowerButtonTimestamp">131010034321473936</Data>
    <Data Name="BootAppStatus">0</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:40:22 PM
Event ID:      7024
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Background Intelligent Transfer Service service terminated with the following service-specific error:
Server execution failed
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7024</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:40:22.631713600Z" />
    <EventRecordID>191</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="2540" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Background Intelligent Transfer Service</Data>
    <Data Name="param2">%%2148007941</Data>
    <Binary>42004900540053000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 10:57:57 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T03:57:57.907799000Z" />
    <EventRecordID>1338</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="6036" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 5:17:18 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:17:18.612545600Z" />
    <EventRecordID>1955</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 5:17:49 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The MBAMScheduler service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:17:49.412748900Z" />
    <EventRecordID>1959</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="544" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">MBAMScheduler</Data>
    <Data Name="param2">%%1053</Data>
    <Binary>4D00420041004D005300630068006500640075006C00650072000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 5:17:49 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the MBAMScheduler service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:17:49.412748900Z" />
    <EventRecordID>1958</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="544" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">MBAMScheduler</Data>
    <Binary>4D00420041004D005300630068006500640075006C00650072000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 10:57:59 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_30937 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T03:57:59.573524100Z" />
    <EventRecordID>1339</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6960" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_30937</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00330030003900330037000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Bits-Client
Date:          25/2/2016 3:40:22 PM
Event ID:      16392
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The BITS service failed to start.  Error 0x80080005.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Bits-Client" Guid="{EF1CC15B-46C1-414E-BB95-E76B077BD51E}" />
    <EventID>16392</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:40:22.632483300Z" />
    <EventRecordID>190</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="1264" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ErrorCode">2148007941</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:59:33 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:59:33.208765800Z" />
    <EventRecordID>3119</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="864" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:49:27 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:49:27.641016700Z" />
    <EventRecordID>2474</EventRecordID>
    <Correlation />
    <Execution ProcessID="744" ThreadID="2000" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 6:46:47 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2617a0f service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T11:46:47.536544400Z" />
    <EventRecordID>785</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="2084" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2617a0f</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0032003600310037006100300066000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 6:46:45 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T11:46:45.835115600Z" />
    <EventRecordID>784</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5524" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:40:22 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          LOCAL SERVICE
Computer:      Mackie
Description:
The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:40:22.241096200Z" />
    <EventRecordID>187</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="1136" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-19" />
  </System>
  <EventData>
    <Data Name="param1">{4991D34B-80A1-4291-83B6-3328366B9097}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:40:22 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:40:22.631713600Z" />
    <EventRecordID>189</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="2684" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{A47979D2-C419-11D9-A5B4-001185AD2B89}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 5:14:13 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_3781b service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T10:14:13.715434100Z" />
    <EventRecordID>752</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="8432" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_3781b</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00330037003800310062000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 5:14:12 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T10:14:12.005772400Z" />
    <EventRecordID>751</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9908" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:15:43 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:15:43.597560700Z" />
    <EventRecordID>2115</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="948" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:50:51 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:50:51.744615000Z" />
    <EventRecordID>3606</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">120000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 7:46:38 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T12:46:38.406099200Z" />
    <EventRecordID>3222</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="1016" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:48:25 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:48:25.670336400Z" />
    <EventRecordID>2429</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="5836" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 5:19:26 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {752073A1-23F2-4396-85F0-8FDB879ED0ED} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:19:26.017855600Z" />
    <EventRecordID>1975</EventRecordID>
    <Correlation />
    <Execution ProcessID="968" ThreadID="2060" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{752073A1-23F2-4396-85F0-8FDB879ED0ED}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 9:38:57 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T14:38:57.773848600Z" />
    <EventRecordID>1383</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="856" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:51:24 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 4 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:51:24.947913800Z" />
    <EventRecordID>3609</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">4</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:24:51 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:24:51.622938500Z" />
    <EventRecordID>2393</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="424" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:50:52 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 300000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:50:52.864141300Z" />
    <EventRecordID>3607</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">2</Data>
    <Data Name="param3">300000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:51:24 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 3 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:51:24.145142000Z" />
    <EventRecordID>3608</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">3</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:48:27 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_c0778 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:48:27.561292000Z" />
    <EventRecordID>2430</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="512" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_c0778</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00630030003700370038000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 11:52:15 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T04:52:15.049451600Z" />
    <EventRecordID>3182</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="5888" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 11:52:16 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_4cc9c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T04:52:16.821881600Z" />
    <EventRecordID>3183</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8132" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_4cc9c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00340063006300390063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:07:43 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the McAfee Boot Delay Start Service service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:07:43.361772800Z" />
    <EventRecordID>494</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="6172" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">McAfee Boot Delay Start Service</Data>
    <Binary>4D00630042006F006F007400440065006C0061007900530074006100720074005300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          27/2/2016 8:41:27 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {CBC04AF1-25C7-4A4D-BB78-28284403510F} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T01:41:27.152665100Z" />
    <EventRecordID>1625</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="988" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{CBC04AF1-25C7-4A4D-BB78-28284403510F}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 11:52:16 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_4cc9c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T04:52:16.821881600Z" />
    <EventRecordID>3184</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8132" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_4cc9c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00340063006300390063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 11:52:16 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_4cc9c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T04:52:16.821881600Z" />
    <EventRecordID>3186</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8132" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_4cc9c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00340063006300390063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:07:43 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee Boot Delay Start Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:07:43.361772800Z" />
    <EventRecordID>495</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="6172" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee Boot Delay Start Service</Data>
    <Data Name="param2">%%1053</Data>
    <Binary>4D00630042006F006F007400440065006C0061007900530074006100720074005300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          27/2/2016 8:39:27 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {4661626C-9F41-40A9-B3F5-5580E80CB347} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T01:39:27.147546800Z" />
    <EventRecordID>1621</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="972" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{4661626C-9F41-40A9-B3F5-5580E80CB347}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 11:52:16 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_4cc9c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T04:52:16.821881600Z" />
    <EventRecordID>3185</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8132" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_4cc9c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00340063006300390063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:55:32 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:55:32.550128600Z" />
    <EventRecordID>2504</EventRecordID>
    <Correlation />
    <Execution ProcessID="744" ThreadID="1412" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 1:16:44 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:44.028667700Z" />
    <EventRecordID>861</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9160" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 4:17:07 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Dell Help & Support service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T21:17:07.918633600Z" />
    <EventRecordID>377</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="6556" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Dell Help &amp; Support</Data>
    <Data Name="param2">%%1053</Data>
    <Binary>440065006C006C002000480065006C00700020002600200053007500700070006F00720074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 1:16:45 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {005A3A96-BAC4-4B0A-94EA-C0CE100EA736} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:45.849081300Z" />
    <EventRecordID>863</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9908" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 1:16:45 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2de9e4e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:45.725252500Z" />
    <EventRecordID>862</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="2084" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2de9e4e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0032006400650039006500340065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:43:12 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:43:12.834317100Z" />
    <EventRecordID>3039</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="472" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:43:25 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:43:25.257447500Z" />
    <EventRecordID>3046</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="424" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 9:03:23 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2a5287c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T14:03:23.202238100Z" />
    <EventRecordID>826</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="976" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2a5287c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0032006100350032003800370063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:56:35 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:56:35.703494000Z" />
    <EventRecordID>2554</EventRecordID>
    <Correlation />
    <Execution ProcessID="748" ThreadID="848" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 4:17:07 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the Dell Help & Support service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T21:17:07.918633600Z" />
    <EventRecordID>376</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="6556" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Dell Help &amp; Support</Data>
    <Binary>440065006C006C002000480065006C00700020002600200053007500700070006F00720074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          1/3/2016 11:24:29 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_3c127d2 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T04:24:29.615283200Z" />
    <EventRecordID>1896</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8268" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_3c127d2</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0033006300310032003700640032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 1:16:55 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:55.582832600Z" />
    <EventRecordID>871</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F04800001000000000000000B0004C0030100000000000000000000160000000000000000000000D5DA390000000000FFFFFFFF0600000058000005000000000000061228090800000000000A0000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B010000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 3:43:02 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:43:02.686680200Z" />
    <EventRecordID>874</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F00800001000000000000000B0004C00301000000000000000000001600000000000000000000009B6A420000000000FFFFFFFF060000005800000500000000000006122801080000000000730000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B000000010000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          1/3/2016 11:24:27 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T04:24:27.830360400Z" />
    <EventRecordID>1895</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="9376" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 1:16:55 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:55.379618700Z" />
    <EventRecordID>870</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F03800001000000000000000B0004C0030100000000000000000000160000000000000000000000C8DA390000000000FFFFFFFF0600000058000005000000000000061228090800000000000A0000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B010000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 1:16:54 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:54.973183200Z" />
    <EventRecordID>868</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F01800001000000000000000B0004C0030100000000000000000000160000000000000000000000AEDA390000000000FFFFFFFF0600000058000005000000000000061228090800000000000A0000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B010000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 1:16:54 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:54.769968800Z" />
    <EventRecordID>867</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F00800001000000000000000B0004C0030100000000000000000000160000000000000000000000A1DA390000000000FFFFFFFF0600000058000005000000000000061228090800000000000A0000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B010000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:38:52 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Network List Service service terminated with the following error:
The device is not ready.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:38:52.617377200Z" />
    <EventRecordID>133</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="708" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Network List Service</Data>
    <Data Name="param2">%%21</Data>
    <Binary>6E0065007400700072006F0066006D000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        disk
Date:          26/2/2016 1:16:55 PM
Event ID:      11
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The driver detected a controller error on \Device\Harddisk1\DR2.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="disk" />
    <EventID Qualifiers="49156">11</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T18:16:55.176403500Z" />
    <EventRecordID>869</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\Harddisk1\DR2</Data>
    <Binary>0F02800001000000000000000B0004C0030100000000000000000000160000000000000000000000BBDA390000000000FFFFFFFF0600000058000005000000000000061228090800000000000A0000000000000000000000C0ED6A1701E0FFFF00000000000000001050452101E0FFFF000000000000000000000000000000001B010000000000000000000000000000000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 9:03:23 AM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T14:03:23.113902900Z" />
    <EventRecordID>825</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5040" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{995C996E-D918-4A8C-A302-45719A6F4EA7}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:58:21 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_3ae0c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:58:21.821421100Z" />
    <EventRecordID>3081</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_3ae0c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00330061006500300063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:58:21 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_3ae0c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:58:21.821421100Z" />
    <EventRecordID>3082</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_3ae0c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00330061006500300063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:58:20 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:58:20.126061300Z" />
    <EventRecordID>3079</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="4780" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:58:21 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_3ae0c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:58:21.821421100Z" />
    <EventRecordID>3080</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_3ae0c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00330061006500300063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:58:21 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_3ae0c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:58:21.821421100Z" />
    <EventRecordID>3083</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_3ae0c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00330061006500300063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:55:45 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:55:45.674279600Z" />
    <EventRecordID>2508</EventRecordID>
    <Correlation />
    <Execution ProcessID="900" ThreadID="1060" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:55:35 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:55:35.662884200Z" />
    <EventRecordID>2505</EventRecordID>
    <Correlation />
    <Execution ProcessID="744" ThreadID="1132" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 8:49:57 AM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {005A3A96-BAC4-4B0A-94EA-C0CE100EA736} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T13:49:57.556858800Z" />
    <EventRecordID>813</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5524" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:55:45 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_9385c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:55:45.909342600Z" />
    <EventRecordID>2509</EventRecordID>
    <Correlation />
    <Execution ProcessID="744" ThreadID="1132" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_9385c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00390033003800350063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        EventLog
Date:          2/3/2016 5:16:35 PM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The previous system shutdown at 4:54:18 PM on ‎3/‎2/‎2016 was unexpected.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:16:35.061139200Z" />
    <EventRecordID>1919</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>4:54:18 PM</Data>
    <Data>‎3/‎2/‎2016</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>332345</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>E007030003000200100036001200AE00E007030003000200150036001200AE00DC0500003C00000001000000DC05000001000000580200000100000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:47:25 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:47:25.350831600Z" />
    <EventRecordID>3069</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="2084" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:47:24 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:47:24.669034800Z" />
    <EventRecordID>3067</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="2084" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:47:24 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:47:24.969798400Z" />
    <EventRecordID>3068</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:50:53 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:50:53.855136700Z" />
    <EventRecordID>3070</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="2084" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 9:03:23 AM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T14:03:23.081315800Z" />
    <EventRecordID>824</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5524" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{995C996E-D918-4A8C-A302-45719A6F4EA7}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 9:03:21 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T14:03:21.514957200Z" />
    <EventRecordID>823</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5524" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:51:14 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:51:14.116348200Z" />
    <EventRecordID>3071</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-WER-SystemErrorReporting
Date:          2/3/2016 5:16:43 PM
Event ID:      1001
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      MACKIE
Description:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000139 (0x0000000000000021, 0xffffd000a34bb420, 0xffffd000a34bb378, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 37172add-faf5-4fb4-be52-48069ccfba6e.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:16:43.702598700Z" />
    <EventRecordID>1923</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>MACKIE</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">0x00000139 (0x0000000000000021, 0xffffd000a34bb420, 0xffffd000a34bb378, 0x0000000000000000)</Data>
    <Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
    <Data Name="param3">37172add-faf5-4fb4-be52-48069ccfba6e</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          27/2/2016 1:17:28 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T18:17:28.728368400Z" />
    <EventRecordID>1550</EventRecordID>
    <Correlation />
    <Execution ProcessID="944" ThreadID="6148" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 5:51:17 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:51:17.043944200Z" />
    <EventRecordID>2045</EventRecordID>
    <Correlation />
    <Execution ProcessID="924" ThreadID="5752" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 10:34:38 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_6cf75 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T03:34:38.083813800Z" />
    <EventRecordID>3369</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="8280" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_6cf75</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00360063006600370035000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 1:17:30 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_4bf16 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T18:17:30.391307900Z" />
    <EventRecordID>1551</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="6784" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_4bf16</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00340062006600310036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 8:48:10 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:10.832232300Z" />
    <EventRecordID>528</EventRecordID>
    <Correlation />
    <Execution ProcessID="900" ThreadID="1424" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:48:12 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The User Data Storage_2d6922 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:12.597712700Z" />
    <EventRecordID>531</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="4256" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_2d6922</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F003200640036003900320032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:48:12 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The User Data Access_2d6922 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:12.597712700Z" />
    <EventRecordID>532</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="4256" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_2d6922</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F003200640036003900320032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:48:12 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2d6922 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:12.597712700Z" />
    <EventRecordID>529</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="4256" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2d6922</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003200640036003900320032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:48:12 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Contact Data_2d6922 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:12.597712700Z" />
    <EventRecordID>530</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="4256" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_2d6922</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F003200640036003900320032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        NETLOGON
Date:          25/2/2016 3:49:21 PM
Event ID:      3095
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="NETLOGON" />
    <EventID Qualifiers="0">3095</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:49:21.835809400Z" />
    <EventRecordID>265</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 8:50:52 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the 0045551456448709mcinstcleanup service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:50:52.488087100Z" />
    <EventRecordID>582</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="976" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">0045551456448709mcinstcleanup</Data>
    <Binary>30003000340035003500350031003400350036003400340038003700300039006D00630069006E007300740063006C00650061006E00750070000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 5:23:18 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-02T22:23:18.549329400Z" />
    <EventRecordID>2016</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="948" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          5/3/2016 4:08:44 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T21:08:44.104630400Z" />
    <EventRecordID>3345</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="2868" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 12:22:24 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T17:22:24.671058500Z" />
    <EventRecordID>1514</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="1060" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 10:34:38 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_6cf75 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T03:34:38.083813800Z" />
    <EventRecordID>3367</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="8280" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_6cf75</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00360063006600370035000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 10:34:38 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_6cf75 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T03:34:38.083813800Z" />
    <EventRecordID>3368</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="8280" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_6cf75</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00360063006600370035000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          5/3/2016 10:34:36 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T03:34:36.433103900Z" />
    <EventRecordID>3365</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="9156" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 10:34:38 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_6cf75 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T03:34:38.083813800Z" />
    <EventRecordID>3366</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="8280" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_6cf75</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00360063006600370035000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          7/3/2016 10:33:05 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The server {005A3A96-BAC4-4B0A-94EA-C0CE100EA736} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:05.655325700Z" />
    <EventRecordID>3712</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="5740" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:21:17 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 26 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:21:17.963480800Z" />
    <EventRecordID>3697</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">26</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:21:06 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 25 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:21:06.328101200Z" />
    <EventRecordID>3696</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">25</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:21:21 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 28 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:21:21.530355200Z" />
    <EventRecordID>3699</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">28</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:21:19 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 27 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:21:19.742209500Z" />
    <EventRecordID>3698</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">27</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:21:05 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 24 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:21:05.668848500Z" />
    <EventRecordID>3695</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6356" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">24</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:51:59 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user MACKIE\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:51:59.856528400Z" />
    <EventRecordID>302</EventRecordID>
    <Correlation />
    <Execution ProcessID="900" ThreadID="6528" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">MACKIE</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:12:40 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:12:40.954806000Z" />
    <EventRecordID>2069</EventRecordID>
    <Correlation />
    <Execution ProcessID="924" ThreadID="7772" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:20:20 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 23 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:20:20.377320600Z" />
    <EventRecordID>3693</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="216" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">23</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:12:42 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_aaa5a service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:12:42.638618500Z" />
    <EventRecordID>2070</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4520" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_aaa5a</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00610061006100350061000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:33:04 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_4a14c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:04.330089100Z" />
    <EventRecordID>3709</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_4a14c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00340061003100340063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:33:04 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_4a14c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:04.330089100Z" />
    <EventRecordID>3708</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_4a14c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00340061003100340063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:33:04 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_4a14c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:04.330089100Z" />
    <EventRecordID>3711</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_4a14c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00340061003100340063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:33:04 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_4a14c service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:04.330089100Z" />
    <EventRecordID>3710</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_4a14c</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00340061003100340063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          7/3/2016 10:33:01 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:33:01.630243300Z" />
    <EventRecordID>3707</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="6968" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:25:34 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 29 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:25:34.658997600Z" />
    <EventRecordID>3701</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="216" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">29</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          6/3/2016 8:49:05 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T13:49:05.639530300Z" />
    <EventRecordID>3406</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="876" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 8:48:17 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:17.828877000Z" />
    <EventRecordID>534</EventRecordID>
    <Correlation />
    <Execution ProcessID="900" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{9BA05972-F6A8-11CF-A442-00A0C90A8F39}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:25:35 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 30 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:25:35.453400800Z" />
    <EventRecordID>3702</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="216" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">30</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 5:11:38 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T10:11:38.270854000Z" />
    <EventRecordID>3752</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="852" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:42:22 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Intel(R) PROSet/Wireless Zero Configuration Service service terminated with the following error:
%%2147770990
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:42:22.837533600Z" />
    <EventRecordID>234</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="1296" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Intel(R) PROSet/Wireless Zero Configuration Service</Data>
    <Data Name="param2">%%2147770990</Data>
    <Binary>5A00650072006F0043006F006E0066006900670053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:56:36 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 12 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:56:36.481662700Z" />
    <EventRecordID>3619</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">12</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:54:21 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 11 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:54:21.435214500Z" />
    <EventRecordID>3617</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6356" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">11</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:55:52 PM
Event ID:      7032
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Software Protection service, but this action failed with the following error:
An instance of the service is already running.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7032</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:55:52.864366200Z" />
    <EventRecordID>3618</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">1</Data>
    <Data Name="param2">Restart the service</Data>
    <Data Name="param3">Software Protection</Data>
    <Data Name="param4">%%1056</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:56:37 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 13 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:56:37.280285200Z" />
    <EventRecordID>3620</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">13</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 11:32:13 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_5f4ac service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T16:32:13.482182800Z" />
    <EventRecordID>3267</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="3420" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_5f4ac</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00350066003400610063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 11:32:13 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_5f4ac service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T16:32:13.482182800Z" />
    <EventRecordID>3268</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="3420" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_5f4ac</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00350066003400610063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:57:14 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 14 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:57:14.652730700Z" />
    <EventRecordID>3621</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">14</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          5/3/2016 11:32:11 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T16:32:11.559241800Z" />
    <EventRecordID>3266</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="4860" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:52:51 PM
Event ID:      7032
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Software Protection service, but this action failed with the following error:
An instance of the service is already running.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7032</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:52:51.799071700Z" />
    <EventRecordID>3612</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">1</Data>
    <Data Name="param2">Restart the service</Data>
    <Data Name="param3">Software Protection</Data>
    <Data Name="param4">%%1056</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:52:53 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 7 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:52:53.809638500Z" />
    <EventRecordID>3613</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6356" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">7</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:52:15 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 5 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:52:15.113765000Z" />
    <EventRecordID>3610</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">5</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:52:15 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 6 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:52:15.886819900Z" />
    <EventRecordID>3611</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">6</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:52:54 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 8 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:52:54.276031700Z" />
    <EventRecordID>3614</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6356" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">8</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:42:20 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Intel(R) Content Protection HDCP Service service terminated with the following error:
Unspecified error
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:42:20.680968600Z" />
    <EventRecordID>231</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="1128" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Intel(R) Content Protection HDCP Service</Data>
    <Data Name="param2">%%2147500037</Data>
    <Binary>630070006C007300700063006F006E000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 8:35:36 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T01:35:36.137775700Z" />
    <EventRecordID>1600</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="1064" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:53:24 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 9 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:53:24.227011200Z" />
    <EventRecordID>3615</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="6356" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">9</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:54:20 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 10 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:54:20.831610200Z" />
    <EventRecordID>3616</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">10</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 11:32:13 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_5f4ac service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T16:32:13.482182800Z" />
    <EventRecordID>3269</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="3420" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_5f4ac</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00350066003400610063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 7:23:54 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_5552e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:23:54.531445700Z" />
    <EventRecordID>2350</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="1448" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_5552e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00350035003500320065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:23:53 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:23:53.234071600Z" />
    <EventRecordID>2349</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="976" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Volsnap
Date:          26/2/2016 12:31:34 AM
Event ID:      36
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Volsnap" Guid="{cb017cd2-1f37-4e65-82bc-3e91f6a37559}" EventSourceName="volsnap" />
    <EventID Qualifiers="49158">36</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T05:31:34.932593200Z" />
    <EventRecordID>643</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="6240" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="DeviceName">\Device\HarddiskVolumeShadowCopy2</Data>
    <Data Name="VolumeName">C:</Data>
    <Data Name="NTSTATUS">00000000</Data>
    <Data Name="SourceTag">164</Data>
    <Data Name="SourceFileID">0x0005</Data>
    <Data Name="SourceLine">2565</Data>
    <Binary>000000000600300000000000240006C0A40000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 3:18:08 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T20:18:08.005800300Z" />
    <EventRecordID>3306</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="548" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:23:52 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:23:52.646009500Z" />
    <EventRecordID>2348</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="964" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{260EB9DE-5CBE-4BFF-A99A-3710AF55BF1E}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:12:38 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 21 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:12:38.233632200Z" />
    <EventRecordID>3630</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">21</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:12:39 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 22 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:12:39.074231400Z" />
    <EventRecordID>3631</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">22</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:23:52 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mca did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:23:52.362886000Z" />
    <EventRecordID>2347</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="964" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">CortanaUI.AppXn73w0hsq3g4wx1h9fhf7q02vw2wta6qc.mca</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 7:23:52 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:23:52.249084300Z" />
    <EventRecordID>2346</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="2000" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          5/3/2016 11:32:13 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_5f4ac service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T16:32:13.482182800Z" />
    <EventRecordID>3270</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="3420" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_5f4ac</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00350066003400610063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:57:15 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 15 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:57:15.343176700Z" />
    <EventRecordID>3622</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="784" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">15</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:44:47 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the Dell Help & Support service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:44:47.462310800Z" />
    <EventRecordID>242</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="1168" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Dell Help &amp; Support</Data>
    <Binary>440065006C006C002000480065006C00700020002600200053007500700070006F00720074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:44:47 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Dell Help & Support service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:44:47.462310800Z" />
    <EventRecordID>243</EventRecordID>
    <Correlation />
    <Execution ProcessID="732" ThreadID="1168" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Dell Help &amp; Support</Data>
    <Data Name="param2">%%1053</Data>
    <Binary>440065006C006C002000480065006C00700020002600200053007500700070006F00720074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 9:58:20 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 16 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T02:58:20.503483300Z" />
    <EventRecordID>3623</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="3168" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">16</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:09:07 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 19 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:09:07.620557100Z" />
    <EventRecordID>3626</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="216" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">19</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:09:08 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 20 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:09:08.294547400Z" />
    <EventRecordID>3627</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="216" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">20</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:08:29 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 17 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:08:29.063858700Z" />
    <EventRecordID>3624</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">17</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 10:08:29 PM
Event ID:      7034
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 18 time(s).
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7034</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T03:08:29.709634400Z" />
    <EventRecordID>3625</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="4316" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">18</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 10:09:21 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_5b492 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T03:09:21.929513600Z" />
    <EventRecordID>1727</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="456" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_5b492</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00350062003400390032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:31:57 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Network List Service service terminated with the following error:
The device is not ready.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:57.009435900Z" />
    <EventRecordID>75</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="1588" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Network List Service</Data>
    <Data Name="param2">%%21</Data>
    <Binary>6E0065007400700072006F0066006D000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:31:55 PM
Event ID:      7024
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Background Intelligent Transfer Service service terminated with the following service-specific error:
Server execution failed
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7024</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:55.732474700Z" />
    <EventRecordID>74</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="1588" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Background Intelligent Transfer Service</Data>
    <Data Name="param2">%%2148007941</Data>
    <Binary>42004900540053000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          27/2/2016 10:09:20 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T03:09:20.262880800Z" />
    <EventRecordID>1726</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="6228" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 6:38:48 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:38:48.803266000Z" />
    <EventRecordID>1141</EventRecordID>
    <Correlation />
    <Execution ProcessID="864" ThreadID="948" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 6:55:27 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:55:27.873761600Z" />
    <EventRecordID>3950</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="856" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 4:24:07 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T21:24:07.551431700Z" />
    <EventRecordID>955</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="5548" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:31:52 PM
Event ID:      7030
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Printer Extensions and Notifications service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7030</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:52.638398600Z" />
    <EventRecordID>70</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="1588" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Printer Extensions and Notifications</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 4:24:09 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2f73736 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T21:24:09.743089300Z" />
    <EventRecordID>956</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="9248" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2f73736</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0032006600370033003700330036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:29:55 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Network List Service service terminated with the following error:
The device is not ready.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:29:55.556670600Z" />
    <EventRecordID>41</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="1596" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Network List Service</Data>
    <Data Name="param2">%%21</Data>
    <Binary>6E0065007400700072006F0066006D000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 7:17:45 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:17:45.994335800Z" />
    <EventRecordID>4014</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="888" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Bits-Client
Date:          25/2/2016 3:31:55 PM
Event ID:      16392
Task Category: None
Level:         Error
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The BITS service failed to start.  Error 0x80080005.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Bits-Client" Guid="{EF1CC15B-46C1-414E-BB95-E76B077BD51E}" />
    <EventID>16392</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:55.735941300Z" />
    <EventRecordID>73</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="1688" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ErrorCode">2148007941</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:31:55 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:55.513700600Z" />
    <EventRecordID>72</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="820" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{A47979D2-C419-11D9-A5B4-001185AD2B89}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:31:55 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          LOCAL SERVICE
Computer:      Mackie
Description:
The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:31:55.513700600Z" />
    <EventRecordID>71</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="952" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-19" />
  </System>
  <EventData>
    <Data Name="param1">{4991D34B-80A1-4291-83B6-3328366B9097}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        EventLog
Date:          26/2/2016 6:38:10 PM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The previous system shutdown at 6:15:12 PM on ‎2/‎26/‎2016 was unexpected.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:38:10.939746100Z" />
    <EventRecordID>1109</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>6:15:12 PM</Data>
    <Data>‎2/‎26/‎2016</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>6624</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>E007020005001A0012000F000C008A02E007020005001A0017000F000C008A02600900003C000000010000006009000001000000B00400000100000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 6:49:39 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:49:39.588001700Z" />
    <EventRecordID>1220</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="756" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        EventLog
Date:          2/3/2016 9:37:05 PM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The previous system shutdown at 9:16:26 PM on ‎3/‎2/‎2016 was unexpected.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T02:37:05.767322100Z" />
    <EventRecordID>2598</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>9:16:26 PM</Data>
    <Data>‎3/‎2/‎2016</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>4816</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>E007030003000200150010001A007B03E007030004000300020010001A007B03600900003C000000010000006009000001000000B00400000100000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 4:32:20 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T21:32:20.691369200Z" />
    <EventRecordID>3568</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="2212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          28/2/2016 11:45:17 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-29T04:45:17.810402700Z" />
    <EventRecordID>1789</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="8060" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          28/2/2016 11:45:20 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_1aa4d24 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-29T04:45:20.089266200Z" />
    <EventRecordID>1790</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="7760" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_1aa4d24</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0031006100610034006400320034000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          6/3/2016 7:44:39 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:39.357119500Z" />
    <EventRecordID>3497</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="8208" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 9:37:24 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T02:37:24.909962000Z" />
    <EventRecordID>2627</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="424" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:32:57 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Intel(R) HD Graphics Control Panel Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:32:57.375297300Z" />
    <EventRecordID>81</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="716" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Intel(R) HD Graphics Control Panel Service</Data>
    <Data Name="param2">%%1053</Data>
    <Binary>6900670066007800430055004900530065007200760069006300650032002E0030002E0030002E0030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:32:57 PM
Event ID:      7009
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
A timeout was reached (30000 milliseconds) while waiting for the Intel(R) HD Graphics Control Panel Service service to connect.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7009</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:32:57.375297300Z" />
    <EventRecordID>80</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="716" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">30000</Data>
    <Data Name="param2">Intel(R) HD Graphics Control Panel Service</Data>
    <Binary>6900670066007800430055004900530065007200760069006300650032002E0030002E0030002E0030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          25/2/2016 3:29:24 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The iphlpsvc service terminated with the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:29:24.334608200Z" />
    <EventRecordID>36</EventRecordID>
    <Correlation />
    <Execution ProcessID="624" ThreadID="1192" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">iphlpsvc</Data>
    <Data Name="param2">%%1058</Data>
    <Binary>6900700068006C0070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          29/2/2016 10:26:25 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-01T03:26:25.999071400Z" />
    <EventRecordID>1815</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="5440" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          29/2/2016 10:26:28 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_2c2f98a service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-01T03:26:28.266394400Z" />
    <EventRecordID>1816</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="7732" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2c2f98a</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0032006300320066003900380061000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 4:50:40 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T21:50:40.394343400Z" />
    <EventRecordID>2949</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="840" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          3/3/2016 10:16:46 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user MACKIE\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:16:46.628289500Z" />
    <EventRecordID>2802</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="8168" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">MACKIE</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 7:08:34 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 2 time(s).  The following corrective action will be taken in 300000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:08:34.316653100Z" />
    <EventRecordID>3983</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="852" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">2</Data>
    <Data Name="param3">300000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        EventLog
Date:          8/3/2016 7:17:46 AM
Event ID:      6008
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The previous system shutdown at 6:55:28 AM on ‎3/‎8/‎2016 was unexpected.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="EventLog" />
    <EventID Qualifiers="32768">6008</EventID>
    <Level>2</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:17:46.244359100Z" />
    <EventRecordID>3984</EventRecordID>
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data>6:55:28 AM</Data>
    <Data>‎3/‎8/‎2016</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Data>14</Data>
    <Data>
    </Data>
    <Data>
    </Data>
    <Binary>E007030002000800060037001C005601E0070300020008000B0037001C0056013C0000003C000000010000003C00000000000000580200000100000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          2/3/2016 11:42:08 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T04:42:08.613711400Z" />
    <EventRecordID>2654</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="1972" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 7:08:33 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Software Protection service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 120000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:08:33.697505900Z" />
    <EventRecordID>3982</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="852" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Software Protection</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">120000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>7300700070007300760063000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          3/3/2016 10:28:05 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:28:05.219224800Z" />
    <EventRecordID>2809</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="7388" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          3/3/2016 10:28:06 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_c50960 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:28:06.989117400Z" />
    <EventRecordID>2810</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8120" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_c50960</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F006300350030003900360030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          3/3/2016 10:28:06 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Contact Data_c50960 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:28:06.989117400Z" />
    <EventRecordID>2811</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8120" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_c50960</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F006300350030003900360030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          3/3/2016 10:28:06 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The User Data Access_c50960 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:28:06.989628900Z" />
    <EventRecordID>2813</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8120" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_c50960</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F006300350030003900360030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          3/3/2016 7:20:43 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T12:20:43.465933600Z" />
    <EventRecordID>2672</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="6336" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          3/3/2016 7:20:45 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_7db123 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T12:20:45.139656300Z" />
    <EventRecordID>2673</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8136" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_7db123</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003700640062003100320033000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 5:38:42 AM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The McAfee SiteAdvisor Service service failed to start due to the following error:
The system cannot find the file specified.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T10:38:42.109770700Z" />
    <EventRecordID>2864</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="656" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">McAfee SiteAdvisor Service</Data>
    <Data Name="param2">%%2</Data>
    <Binary>4D006300410066006500650020005300690074006500410064007600690073006F007200200053006500720076006900630065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 11:42:11 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_56a77b service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T04:42:11.061138100Z" />
    <EventRecordID>2655</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="6012" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_56a77b</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003500360061003700370062000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          3/3/2016 10:28:06 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The User Data Storage_c50960 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:28:06.989628900Z" />
    <EventRecordID>2812</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="8120" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_c50960</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F006300350030003900360030000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-WER-SystemErrorReporting
Date:          8/3/2016 7:17:57 AM
Event ID:      1001
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000139 (0x0000000000000021, 0xffffd0014585c420, 0xffffd0014585c378, 0x0000000000000000). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 7ae8f3e9-9a3b-4912-89df-acd7ae01c25b.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
    <EventID Qualifiers="16384">1001</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T12:17:57.713877800Z" />
    <EventRecordID>3988</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">0x00000139 (0x0000000000000021, 0xffffd0014585c420, 0xffffd0014585c378, 0x0000000000000000)</Data>
    <Data Name="param2">C:\WINDOWS\MEMORY.DMP</Data>
    <Data Name="param3">7ae8f3e9-9a3b-4912-89df-acd7ae01c25b</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 7:05:05 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_2bdd1e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T12:05:05.381120500Z" />
    <EventRecordID>2904</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="76" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_2bdd1e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F003200620064006400310065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 7:05:05 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_2bdd1e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T12:05:05.381120500Z" />
    <EventRecordID>2903</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="76" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_2bdd1e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F003200620064006400310065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 7:05:05 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_2bdd1e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T12:05:05.381120500Z" />
    <EventRecordID>2902</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="76" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_2bdd1e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003200620064006400310065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 7:05:05 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_2bdd1e service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T12:05:05.381120500Z" />
    <EventRecordID>2905</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="76" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_2bdd1e</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F003200620064006400310065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 4:24:12 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T21:24:12.074687100Z" />
    <EventRecordID>959</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="8796" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">{9BA05972-F6A8-11CF-A442-00A0C90A8F39}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          1/3/2016 4:41:06 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_37b4c83 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-01T21:41:06.917846000Z" />
    <EventRecordID>1842</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="660" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_37b4c83</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F0033003700620034006300380033000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          1/3/2016 4:41:05 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-01T21:41:05.233287200Z" />
    <EventRecordID>1841</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="1232" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 6:48:26 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The server CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:48:26.019245700Z" />
    <EventRecordID>1178</EventRecordID>
    <Correlation />
    <Execution ProcessID="1020" ThreadID="1160" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 6:48:24 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_73b2d service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:48:24.147230400Z" />
    <EventRecordID>1177</EventRecordID>
    <Correlation />
    <Execution ProcessID="864" ThreadID="1068" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_73b2d</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00370033006200320064000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 6:48:22 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T23:48:22.478630400Z" />
    <EventRecordID>1176</EventRecordID>
    <Correlation />
    <Execution ProcessID="1020" ThreadID="5860" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 4:30:54 PM
Event ID:      7000
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The luafv service failed to start due to the following error:
This driver has been blocked from loading
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7000</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T21:30:54.168846800Z" />
    <EventRecordID>3538</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="864" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">luafv</Data>
    <Data Name="param2">%%1275</Data>
    <Binary>6C0075006100660076000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 7:05:03 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T12:05:03.554887700Z" />
    <EventRecordID>2901</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="5500" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          3/3/2016 10:16:46 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      Mackie
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user MACKIE\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T03:16:46.636310800Z" />
    <EventRecordID>2803</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="8168" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">MACKIE</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 4:31:33 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T21:31:33.155518200Z" />
    <EventRecordID>3562</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="856" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 8:02:55 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T01:02:55.090459100Z" />
    <EventRecordID>2585</EventRecordID>
    <Correlation />
    <Execution ProcessID="748" ThreadID="416" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 6:54:36 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_3c1b02 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:54:36.149804100Z" />
    <EventRecordID>3911</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="5024" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_3c1b02</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003300630031006200300032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          6/3/2016 7:44:41 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_151fae service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:41.041804100Z" />
    <EventRecordID>3499</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="7400" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_151fae</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F003100350031006600610065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 6:54:36 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_3c1b02 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:54:36.149804100Z" />
    <EventRecordID>3912</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="5024" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_3c1b02</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F003300630031006200300032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:34 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:34.383852100Z" />
    <EventRecordID>888</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9928" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          8/3/2016 6:54:34 AM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:54:34.202143700Z" />
    <EventRecordID>3910</EventRecordID>
    <Correlation />
    <Execution ProcessID="932" ThreadID="6512" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 4:47:49 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T21:47:49.022055000Z" />
    <EventRecordID>1081</EventRecordID>
    <Correlation />
    <Execution ProcessID="1016" ThreadID="6748" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 6:54:36 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_3c1b02 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:54:36.149804100Z" />
    <EventRecordID>3913</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="5024" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_3c1b02</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F003300630031006200300032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:38:44 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:44.150045800Z" />
    <EventRecordID>2992</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:34 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:34.909435800Z" />
    <EventRecordID>889</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9928" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:35 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:35.488933600Z" />
    <EventRecordID>890</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          8/3/2016 6:54:36 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_3c1b02 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-08T11:54:36.150305000Z" />
    <EventRecordID>3914</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="5024" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_3c1b02</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F003300630031006200300032000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:39:05 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:39:05.464004300Z" />
    <EventRecordID>2994</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:39:04 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:39:04.110881200Z" />
    <EventRecordID>2993</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="432" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:33 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:33.843776200Z" />
    <EventRecordID>887</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9928" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 8:01:03 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T01:01:03.537697600Z" />
    <EventRecordID>2574</EventRecordID>
    <Correlation />
    <Execution ProcessID="748" ThreadID="824" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          6/3/2016 7:44:41 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_151fae service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:41.041804100Z" />
    <EventRecordID>3501</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="7400" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_151fae</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F003100350031006600610065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:42:26 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Access_9f1d6 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:26.273995700Z" />
    <EventRecordID>3004</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Access_9f1d6</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>550073006500720044006100740061005300760063005F00390066003100640036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 8:00:34 PM
Event ID:      7024
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Remote Access Connection Manager service terminated with the following service-specific error:
This operation returned because the timeout period expired.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7024</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T01:00:34.381781900Z" />
    <EventRecordID>2572</EventRecordID>
    <Correlation />
    <Execution ProcessID="748" ThreadID="824" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Remote Access Connection Manager</Data>
    <Data Name="param2">%%2147943860</Data>
    <Binary>5200610073004D0061006E000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:33:57 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:33:57.031081100Z" />
    <EventRecordID>126</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="820" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">{A47979D2-C419-11D9-A5B4-001185AD2B89}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          25/2/2016 3:33:55 PM
Event ID:      10010
Task Category: None
Level:         Error
Keywords:      Classic
User:          LOCAL SERVICE
Computer:      Mackie
Description:
The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10010</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T20:33:55.546167000Z" />
    <EventRecordID>125</EventRecordID>
    <Correlation />
    <Execution ProcessID="784" ThreadID="952" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-19" />
  </System>
  <EventData>
    <Data Name="param1">{4991D34B-80A1-4291-83B6-3328366B9097}</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:42:26 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_9f1d6 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:26.273995700Z" />
    <EventRecordID>3003</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_9f1d6</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F00390066003100640036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          6/3/2016 7:44:41 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The User Data Storage_151fae service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:41.041804100Z" />
    <EventRecordID>3500</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="7400" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">User Data Storage_151fae</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>55006E006900730074006F00720065005300760063005F003100350031006600610065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          26/2/2016 4:47:50 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_3b42d service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T21:47:50.832388800Z" />
    <EventRecordID>1082</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="2556" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_3b42d</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00330062003400320064000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:32 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:32.829237500Z" />
    <EventRecordID>886</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9712" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:42:26 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Contact Data_9f1d6 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:26.273995700Z" />
    <EventRecordID>3002</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Contact Data_9f1d6</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>500069006D0049006E006400650078004D00610069006E00740065006E0061006E00630065005300760063005F00390066003100640036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:42:26 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_9f1d6 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:26.273995700Z" />
    <EventRecordID>3001</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="9212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_9f1d6</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00390066003100640036000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:42:25 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      ALIOU
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:25.684320300Z" />
    <EventRecordID>3000</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="6976" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          6/3/2016 7:44:41 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Sync Host_151fae service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:41.041804100Z" />
    <EventRecordID>3498</EventRecordID>
    <Correlation />
    <Execution ProcessID="780" ThreadID="7400" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_151fae</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F003100350031006600610065000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:37 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:37.039288700Z" />
    <EventRecordID>893</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          27/2/2016 12:21:25 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_36b27 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T17:21:25.662575500Z" />
    <EventRecordID>1471</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="7268" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_36b27</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F00330036006200320037000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:36 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:36.001924300Z" />
    <EventRecordID>891</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          28/2/2016 12:05:34 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T17:05:34.279811700Z" />
    <EventRecordID>1755</EventRecordID>
    <Correlation />
    <Execution ProcessID="940" ThreadID="2828" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          7/3/2016 4:32:24 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T21:32:24.247062000Z" />
    <EventRecordID>3571</EventRecordID>
    <Correlation />
    <Execution ProcessID="768" ThreadID="2212" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          2/3/2016 8:02:50 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T01:02:50.848117100Z" />
    <EventRecordID>2584</EventRecordID>
    <Correlation />
    <Execution ProcessID="748" ThreadID="416" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:38 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:38.108332700Z" />
    <EventRecordID>895</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:37 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:37.565425900Z" />
    <EventRecordID>894</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          27/2/2016 12:21:23 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          SYSTEM
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T17:21:23.318423300Z" />
    <EventRecordID>1470</EventRecordID>
    <Correlation />
    <Execution ProcessID="920" ThreadID="6504" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{D63B10C5-BB46-4990-A94F-E40B9D520160}</Data>
    <Data Name="param5">{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">SYSTEM</Data>
    <Data Name="param8">S-1-5-18</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          28/2/2016 12:05:35 PM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The Sync Host_d179ab service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7031</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-28T17:05:35.986699700Z" />
    <EventRecordID>1756</EventRecordID>
    <Correlation />
    <Execution ProcessID="772" ThreadID="3260" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Sync Host_d179ab</Data>
    <Data Name="param2">1</Data>
    <Data Name="param3">10000</Data>
    <Data Name="param4">1</Data>
    <Data Name="param5">Restart the service</Data>
    <Binary>4F006E006500530079006E0063005300760063005F006400310037003900610062000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.685443700Z" />
    <EventRecordID>2985</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="1920" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.698981000Z" />
    <EventRecordID>2988</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="1920" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.698981000Z" />
    <EventRecordID>2989</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="3236" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          26/2/2016 3:44:36 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NETWORK SERVICE
Computer:      Mackie
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{3185A766-B338-11E4-A71E-12E3F512A338}
 and APPID
{7006698D-2974-4091-A424-85DD0B909E23}
 to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:36.528550400Z" />
    <EventRecordID>892</EventRecordID>
    <Correlation />
    <Execution ProcessID="192" ThreadID="9284" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{3185A766-B338-11E4-A71E-12E3F512A338}</Data>
    <Data Name="param5">{7006698D-2974-4091-A424-85DD0B909E23}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">NETWORK SERVICE</Data>
    <Data Name="param8">S-1-5-20</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.685443700Z" />
    <EventRecordID>2986</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="8624" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:38:00 PM
Event ID:      7030
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Dell Click 2 Fix+ service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7030</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:00.445524100Z" />
    <EventRecordID>2982</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="2508" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Dell Click 2 Fix+</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.698981000Z" />
    <EventRecordID>2987</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="8624" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Service Control Manager
Date:          4/3/2016 8:38:00 PM
Event ID:      7023
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
The Interactive Services Detection service terminated with the following error:
Incorrect function.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
    <EventID Qualifiers="49152">7023</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:00.747035100Z" />
    <EventRecordID>2983</EventRecordID>
    <Correlation />
    <Execution ProcessID="776" ThreadID="2508" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="param1">Interactive Services Detection</Data>
    <Data Name="param2">%%1</Data>
    <Binary>5500490030004400650074006500630074000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          4/3/2016 8:38:06 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          ALIOU\Mackie
Computer:      ALIOU
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user ALIOU\Mackie SID (S-1-5-21-255578287-951111391-1555935064-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:38:06.685443700Z" />
    <EventRecordID>2984</EventRecordID>
    <Correlation />
    <Execution ProcessID="928" ThreadID="3236" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-21-255578287-951111391-1555935064-1001" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{C2F03A33-21F5-47FA-B4BB-156362A2F239}</Data>
    <Data Name="param5">{316CDED5-E4AE-4B15-9113-7055D84DCC97}</Data>
    <Data Name="param6">ALIOU</Data>
    <Data Name="param7">Mackie</Data>
    <Data Name="param8">S-1-5-21-255578287-951111391-1555935064-1001</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewy</Data>
    <Data Name="param11">S-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\taskhostw.exe with process id 4168 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411994900Z" />
    <EventRecordID>2195</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4168</Data>
    <Data Name="ProcessNameLength">54</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\taskhostw.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\sihost.exe with process id 4132 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411993600Z" />
    <EventRecordID>2194</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4132</Data>
    <Data Name="ProcessNameLength">51</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\sihost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe with process id 2080 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447585200Z" />
    <EventRecordID>2266</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2080</Data>
    <Data Name="ProcessNameLength">95</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe with process id 4200 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411996200Z" />
    <EventRecordID>2196</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4200</Data>
    <Data Name="ProcessNameLength">86</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RAVBg64.exe with process id 1720 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447574600Z" />
    <EventRecordID>2258</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1720</Data>
    <Data Name="ProcessNameLength">67</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RAVBg64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe with process id 2068 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447583900Z" />
    <EventRecordID>2265</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2068</Data>
    <Data Name="ProcessNameLength">71</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\EvtEng.exe with process id 2060 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447582700Z" />
    <EventRecordID>2264</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2060</Data>
    <Data Name="ProcessNameLength">63</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\EvtEng.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe with process id 2164 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447586900Z" />
    <EventRecordID>2267</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2164</Data>
    <Data Name="ProcessNameLength">66</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SysWOW64\IntelCpHeciSvc.exe with process id 1912 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447579700Z" />
    <EventRecordID>2262</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1912</Data>
    <Data Name="ProcessNameLength">59</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SysWOW64\IntelCpHeciSvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wlanext.exe with process id 2292 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447588200Z" />
    <EventRecordID>2268</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2292</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wlanext.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe with process id 2052 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447581400Z" />
    <EventRecordID>2263</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2052</Data>
    <Data Name="ProcessNameLength">83</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\SearchProtocolHost.exe with process id 1856 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447578800Z" />
    <EventRecordID>2261</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1856</Data>
    <Data Name="ProcessNameLength">63</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\SearchProtocolHost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RAVBg64.exe with process id 1744 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447575800Z" />
    <EventRecordID>2259</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1744</Data>
    <Data Name="ProcessNameLength">67</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RAVBg64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 2340 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447589500Z" />
    <EventRecordID>2269</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2340</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\spoolsv.exe with process id 1824 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447577100Z" />
    <EventRecordID>2260</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1824</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\spoolsv.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe with process id 3588 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411992300Z" />
    <EventRecordID>2193</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3588</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\conhost.exe with process id 2368 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447590800Z" />
    <EventRecordID>2270</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2368</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\conhost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe with process id 2456 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411975300Z" />
    <EventRecordID>2180</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2456</Data>
    <Data Name="ProcessNameLength">90</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe with process id 2612 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447599300Z" />
    <EventRecordID>2277</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2612</Data>
    <Data Name="ProcessNameLength">77</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-WLAN-AutoConfig
Date:          25/2/2016 8:48:57 PM
Event ID:      10002
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\IWMSSvc.dll

Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-WLAN-AutoConfig" Guid="{9580D7DD-0379-4658-9870-D5BE7D52D6DE}" />
    <EventID>10002</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:48:57.313023000Z" />
    <EventRecordID>539</EventRecordID>
    <Correlation />
    <Execution ProcessID="1060" ThreadID="3492" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ExtensibleModulePath">C:\WINDOWS\System32\IWMSSvc.dll</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe with process id 2572 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447598500Z" />
    <EventRecordID>2276</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2572</Data>
    <Data Name="ProcessNameLength">95</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe with process id 2544 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411979100Z" />
    <EventRecordID>2183</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2544</Data>
    <Data Name="ProcessNameLength">85</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFSSvc.exe with process id 2528 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411977800Z" />
    <EventRecordID>2182</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2528</Data>
    <Data Name="ProcessNameLength">78</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFSSvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe with process id 2484 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411976600Z" />
    <EventRecordID>2181</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2484</Data>
    <Data Name="ProcessNameLength">87</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\conhost.exe with process id 2368 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411974000Z" />
    <EventRecordID>2179</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2368</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\conhost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe with process id 3440 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447606100Z" />
    <EventRecordID>2282</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3440</Data>
    <Data Name="ProcessNameLength">144</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\unsecapp.exe with process id 3540 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447607400Z" />
    <EventRecordID>2283</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3540</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\unsecapp.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe with process id 3588 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447608700Z" />
    <EventRecordID>2284</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3588</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Windows Defender\NisSrv.exe with process id 3132 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447604400Z" />
    <EventRecordID>2281</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3132</Data>
    <Data Name="ProcessNameLength">65</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Windows Defender\NisSrv.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\msiexec.exe with process id 2668 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447600600Z" />
    <EventRecordID>2278</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2668</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe with process id 2708 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447601900Z" />
    <EventRecordID>2279</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2708</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\taskeng.exe with process id 2928 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447603100Z" />
    <EventRecordID>2280</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2928</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\taskeng.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe with process id 3440 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411989800Z" />
    <EventRecordID>2191</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3440</Data>
    <Data Name="ProcessNameLength">144</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Windows Defender\NisSrv.exe with process id 3132 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411988500Z" />
    <EventRecordID>2190</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3132</Data>
    <Data Name="ProcessNameLength">65</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Windows Defender\NisSrv.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\taskeng.exe with process id 2928 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411986800Z" />
    <EventRecordID>2189</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2928</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\taskeng.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\unsecapp.exe with process id 3540 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411991100Z" />
    <EventRecordID>2192</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">3540</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\unsecapp.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe with process id 2456 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447592100Z" />
    <EventRecordID>2271</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2456</Data>
    <Data Name="ProcessNameLength">90</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe with process id 2484 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447593300Z" />
    <EventRecordID>2272</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2484</Data>
    <Data Name="ProcessNameLength">87</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-WLAN-AutoConfig
Date:          6/3/2016 7:44:48 PM
Event ID:      10002
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      ALIOU
Description:
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\IWMSSvc.dll

Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-WLAN-AutoConfig" Guid="{9580D7DD-0379-4658-9870-D5BE7D52D6DE}" />
    <EventID>10002</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-07T00:44:48.715890400Z" />
    <EventRecordID>3506</EventRecordID>
    <Correlation />
    <Execution ProcessID="8" ThreadID="7644" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ExtensibleModulePath">C:\WINDOWS\System32\IWMSSvc.dll</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe with process id 2708 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411985500Z" />
    <EventRecordID>2188</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2708</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\ZeroConfigService.exe with process id 2564 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447596700Z" />
    <EventRecordID>2275</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2564</Data>
    <Data Name="ProcessNameLength">74</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\ZeroConfigService.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe with process id 2572 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411981700Z" />
    <EventRecordID>2185</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2572</Data>
    <Data Name="ProcessNameLength">95</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\ZeroConfigService.exe with process id 2564 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411980400Z" />
    <EventRecordID>2184</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2564</Data>
    <Data Name="ProcessNameLength">74</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Intel\WiFi\bin\ZeroConfigService.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe with process id 2544 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447595900Z" />
    <EventRecordID>2274</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2544</Data>
    <Data Name="ProcessNameLength">85</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\msiexec.exe with process id 2668 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411984200Z" />
    <EventRecordID>2187</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2668</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFSSvc.exe with process id 2528 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447594600Z" />
    <EventRecordID>2273</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2528</Data>
    <Data Name="ProcessNameLength">78</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFSSvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe with process id 2612 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411983000Z" />
    <EventRecordID>2186</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">2612</Data>
    <Data Name="ProcessNameLength">77</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wininit.exe with process id 660 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447546800Z" />
    <EventRecordID>2237</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">660</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wininit.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        mfehidk
Date:          25/2/2016 8:06:32 PM
Event ID:      516
Task Category: (256)
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The description for Event ID 516 from source mfehidk cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

If the event originated on another computer, the display information had to be saved with the event.

The following information was included with the event:

\Device\mfehidk
**\MCUPDA~1.EXE
8772

Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="mfehidk" />
    <EventID Qualifiers="33024">516</EventID>
    <Level>3</Level>
    <Task>256</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T01:06:32.012577500Z" />
    <EventRecordID>490</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\mfehidk</Data>
    <Data>**\MCUPDA~1.EXE</Data>
    <Data>8772</Data>
    <Binary>00000000030030000001000004020081000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\Product Registration\PRSvc.exe with process id 6056 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412020500Z" />
    <EventRecordID>2216</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6056</Data>
    <Data Name="ProcessNameLength">73</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\Product Registration\PRSvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\msiexec.exe with process id 6112 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412021800Z" />
    <EventRecordID>2217</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6112</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 580 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447544300Z" />
    <EventRecordID>2235</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">580</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\csrss.exe with process id 636 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447545500Z" />
    <EventRecordID>2236</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">636</Data>
    <Data Name="ProcessNameLength">50</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\csrss.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\audiodg.exe with process id 6116 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412023100Z" />
    <EventRecordID>2218</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6116</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\audiodg.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\winlogon.exe with process id 716 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447548100Z" />
    <EventRecordID>2238</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">716</Data>
    <Data Name="ProcessNameLength">53</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\winlogon.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 840 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447551500Z" />
    <EventRecordID>2241</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">840</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 868 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447552800Z" />
    <EventRecordID>2242</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">868</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 928 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447554900Z" />
    <EventRecordID>2243</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">928</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\SearchIndexer.exe with process id 5724 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412018400Z" />
    <EventRecordID>2214</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5724</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\SearchIndexer.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Common Files\Java\Java Update\jusched.exe with process id 5760 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412019700Z" />
    <EventRecordID>2215</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5760</Data>
    <Data Name="ProcessNameLength">85</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Common Files\Java\Java Update\jusched.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\services.exe with process id 768 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447549400Z" />
    <EventRecordID>2239</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">768</Data>
    <Data Name="ProcessNameLength">53</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\services.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\lsass.exe with process id 776 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447550700Z" />
    <EventRecordID>2240</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">776</Data>
    <Data Name="ProcessNameLength">50</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\lsass.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\csrss.exe with process id 556 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447543000Z" />
    <EventRecordID>2234</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">556</Data>
    <Data Name="ProcessNameLength">50</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\csrss.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\WmiApSrv.exe with process id 6904 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412029500Z" />
    <EventRecordID>2223</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6904</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\WmiApSrv.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 6928 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412030700Z" />
    <EventRecordID>2224</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6928</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe with process id 7136 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412032000Z" />
    <EventRecordID>2225</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">7136</Data>
    <Data Name="ProcessNameLength">115</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe with process id 6628 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412028600Z" />
    <EventRecordID>2222</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6628</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SysWOW64\msiexec.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Users\Mackie\Downloads\Serial-ATA_Driver_K07VX_WN32_14.8.1.1043_A02.EXE with process id 6396 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412027300Z" />
    <EventRecordID>2221</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6396</Data>
    <Data Name="ProcessNameLength">95</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Users\Mackie\Downloads\Serial-ATA_Driver_K07VX_WN32_14.8.1.1043_A02.EXE</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\ProgramData\Dell\drivers\Serial-ATA_Driver_K07VX_WN32_14.8.1.1043_A02\SetupRST.exe with process id 6360 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412026100Z" />
    <EventRecordID>2220</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6360</Data>
    <Data Name="ProcessNameLength">106</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\ProgramData\Dell\drivers\Serial-ATA_Driver_K07VX_WN32_14.8.1.1043_A02\SetupRST.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVault.exe with process id 6276 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412024300Z" />
    <EventRecordID>2219</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">6276</Data>
    <Data Name="ProcessNameLength">74</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\DellDataVault\DellDataVault.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          6/3/2016 11:17:35 AM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-06T16:17:35.820525800Z" />
    <EventRecordID>3467</EventRecordID>
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 432 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447540400Z" />
    <EventRecordID>2232</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">432</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 520 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447541700Z" />
    <EventRecordID>2233</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">520</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-DNS-Client
Date:          25/2/2016 6:53:09 PM
Event ID:      1014
Task Category: (1014)
Level:         Warning
Keywords:      (268435456)
User:          NETWORK SERVICE
Computer:      Mackie
Description:
Name resolution for the name s.kau.li timed out after none of the configured DNS servers responded.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-DNS-Client" Guid="{1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}" />
    <EventID>1014</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>1014</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000010000000</Keywords>
    <TimeCreated SystemTime="2016-02-25T23:53:09.136769900Z" />
    <EventRecordID>485</EventRecordID>
    <Correlation />
    <Execution ProcessID="1436" ThreadID="1500" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-20" />
  </System>
  <EventData>
    <Data Name="QueryName">s.kau.li</Data>
    <Data Name="AddressLength">128</Data>
    <Data Name="Address">0200000041B7004C000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\smss.exe with process id 396 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447538700Z" />
    <EventRecordID>2231</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">396</Data>
    <Data Name="ProcessNameLength">49</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\smss.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application System with process id 4 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447528900Z" />
    <EventRecordID>2228</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4</Data>
    <Data Name="ProcessNameLength">6</Data>
    <Data Name="ProcessName">System</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe with process id 76 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447535300Z" />
    <EventRecordID>2229</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">76</Data>
    <Data Name="ProcessNameLength">102</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe with process id 284 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447537400Z" />
    <EventRecordID>2230</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">284</Data>
    <Data Name="ProcessNameLength">67</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 1120 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447560100Z" />
    <EventRecordID>2247</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1120</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Waves\MaxxAudio\WavesSvc64.exe with process id 1156 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447561300Z" />
    <EventRecordID>2248</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1156</Data>
    <Data Name="ProcessNameLength">68</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Waves\MaxxAudio\WavesSvc64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\SearchFilterHost.exe with process id 1188 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447563000Z" />
    <EventRecordID>2249</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1188</Data>
    <Data Name="ProcessNameLength">61</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\SearchFilterHost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\RuntimeBroker.exe with process id 4244 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411997500Z" />
    <EventRecordID>2197</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4244</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\RuntimeBroker.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe with process id 4316 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412000000Z" />
    <EventRecordID>2199</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4316</Data>
    <Data Name="ProcessNameLength">78</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\igfxEM.exe with process id 4300 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.411998700Z" />
    <EventRecordID>2198</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4300</Data>
    <Data Name="ProcessNameLength">51</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\igfxEM.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 1096 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447558800Z" />
    <EventRecordID>2246</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1096</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Breakaway\breakaway.exe with process id 1280 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447564300Z" />
    <EventRecordID>2250</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1280</Data>
    <Data Name="ProcessNameLength">67</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Breakaway\breakaway.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 1480 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447570700Z" />
    <EventRecordID>2255</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1480</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgsvca.exe with process id 1648 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447572000Z" />
    <EventRecordID>2256</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1648</Data>
    <Data Name="ProcessNameLength">76</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avgsvca.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe with process id 1668 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447573300Z" />
    <EventRecordID>2257</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1668</Data>
    <Data Name="ProcessNameLength">77</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe with process id 1388 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447569400Z" />
    <EventRecordID>2254</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1388</Data>
    <Data Name="ProcessNameLength">71</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Mozilla Firefox\firefox.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\igfxCUIService.exe with process id 1292 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447565600Z" />
    <EventRecordID>2251</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1292</Data>
    <Data Name="ProcessNameLength">59</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\igfxCUIService.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\Dell Help & Support\MDLCSvc.exe with process id 1344 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447566900Z" />
    <EventRecordID>2252</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1344</Data>
    <Data Name="ProcessNameLength">74</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\Dell Help &amp; Support\MDLCSvc.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 1360 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447568200Z" />
    <EventRecordID>2253</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1360</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\dwm.exe with process id 1004 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447557500Z" />
    <EventRecordID>2245</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">1004</Data>
    <Data Name="ProcessNameLength">48</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\dwm.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe with process id 5168 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412013700Z" />
    <EventRecordID>2210</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5168</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avguix.exe with process id 5124 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412012400Z" />
    <EventRecordID>2209</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5124</Data>
    <Data Name="ProcessNameLength">75</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\AVG\Framework\Common\avguix.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\explorer.exe with process id 4976 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412011100Z" />
    <EventRecordID>2208</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4976</Data>
    <Data Name="ProcessNameLength">44</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\explorer.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\drvinst.exe with process id 5192 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412015000Z" />
    <EventRecordID>2211</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5192</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\drvinst.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\servicing\TrustedInstaller.exe with process id 5308 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412017100Z" />
    <EventRecordID>2213</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5308</Data>
    <Data Name="ProcessNameLength">62</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\servicing\TrustedInstaller.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:50 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 992 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:50.447556200Z" />
    <EventRecordID>2244</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="1984" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">992</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe with process id 5260 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412015800Z" />
    <EventRecordID>2212</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">5260</Data>
    <Data Name="ProcessNameLength">58</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\wbem\WmiPrvSE.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe with process id 4880 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412009800Z" />
    <EventRecordID>2207</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4880</Data>
    <Data Name="ProcessNameLength">88</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe with process id 4640 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412003400Z" />
    <EventRecordID>2202</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4640</Data>
    <Data Name="ProcessNameLength">92</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\igfxHK.exe with process id 4464 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412002600Z" />
    <EventRecordID>2201</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4464</Data>
    <Data Name="ProcessNameLength">51</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\igfxHK.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\svchost.exe with process id 4424 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412001300Z" />
    <EventRecordID>2200</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4424</Data>
    <Data Name="ProcessNameLength">52</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\svchost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Program Files (x86)\Breakaway\breakaway.exe with process id 4752 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412005100Z" />
    <EventRecordID>2203</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4752</Data>
    <Data Name="ProcessNameLength">67</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Program Files (x86)\Breakaway\breakaway.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\igfxTray.exe with process id 4840 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412008600Z" />
    <EventRecordID>2206</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4840</Data>
    <Data Name="ProcessNameLength">53</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\igfxTray.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\System32\VSSVC.exe with process id 4768 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412007300Z" />
    <EventRecordID>2205</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4768</Data>
    <Data Name="ProcessNameLength">50</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\System32\VSSVC.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-Kernel-PnP
Date:          2/3/2016 7:21:40 PM
Event ID:      225
Task Category: (223)
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Mackie
Description:
The application \Device\HarddiskVolume3\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe with process id 4764 stopped the removal or ejection for the device PCI\VEN_8086&DEV_9D03&SUBSYS_06B21028&REV_21\3&11583659&0&B8.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-PnP" Guid="{9C205A39-1250-487D-ABD7-E831C6290539}" />
    <EventID>225</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>223</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-03T00:21:40.412006400Z" />
    <EventRecordID>2204</EventRecordID>
    <Correlation />
    <Execution ProcessID="4" ThreadID="4360" />
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ProcessId">4764</Data>
    <Data Name="ProcessNameLength">100</Data>
    <Data Name="ProcessName">\Device\HarddiskVolume3\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe</Data>
    <Data Name="DeviceInstanceLength">60</Data>
    <Data Name="DeviceInstance">PCI\VEN_8086&amp;DEV_9D03&amp;SUBSYS_06B21028&amp;REV_21\3&amp;11583659&amp;0&amp;B8</Data>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          26/2/2016 3:44:21 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:44:21.503520900Z" />
    <EventRecordID>885</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        i8042prt
Date:          26/2/2016 3:43:12 PM
Event ID:      18
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
The device sent an incorrect response(s) following a mouse reset.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="i8042prt" />
    <EventID Qualifiers="32773">18</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-26T20:43:12.879874700Z" />
    <EventRecordID>883</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>
    </Data>
    <Binary>000010000100000000000000120005808C050000B50000C0000000000000000000000000000000000400000000000000AA00000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          4/3/2016 6:57:50 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-04T23:57:50.923622900Z" />
    <EventRecordID>2976</EventRecordID>
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          4/3/2016 8:30:06 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      ALIOU
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:30:06.588807700Z" />
    <EventRecordID>2980</EventRecordID>
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        Microsoft-Windows-WLAN-AutoConfig
Date:          4/3/2016 8:42:35 PM
Event ID:      10002
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      ALIOU
Description:
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\IWMSSvc.dll

Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="Microsoft-Windows-WLAN-AutoConfig" Guid="{9580D7DD-0379-4658-9870-D5BE7D52D6DE}" />
    <EventID>10002</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x4000000000000000</Keywords>
    <TimeCreated SystemTime="2016-03-05T01:42:35.170624200Z" />
    <EventRecordID>3009</EventRecordID>
    <Correlation />
    <Execution ProcessID="368" ThreadID="8384" />
    <Channel>System</Channel>
    <Computer>ALIOU</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="ExtensibleModulePath">C:\WINDOWS\System32\IWMSSvc.dll</Data>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          26/2/2016 7:10:23 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T00:10:23.285641400Z" />
    <EventRecordID>1252</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          26/2/2016 8:34:31 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T01:34:31.423228600Z" />
    <EventRecordID>1253</EventRecordID>
    <Channel>System</Channel>
    <Computer>Mackie</Computer>
    <Security />
  </System>
  <EventData>
    <Data>\Device\NDMP2</Data>
    <Data>Realtek PCIe FE Family Controller</Data>
    <Binary>00000000020030000000000001000080000000000000000000000000000000000000000000000000</Binary>
  </EventData>
</Event>

Log Name:      System
Source:        rt640x64
Date:          26/2/2016 7:02:39 PM
Event ID:      1
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      Mackie
Description:
Realtek PCIe FE Family Controller is disconnected from network.
Event Xml:
<Event xmlns="schemas.microsoft.com/.../event">
  <System>
    <Provider Name="rt640x64" />
    <EventID Qualifiers="32768">1</EventID>
    <Level>3</Level>
    <Task>0</Task>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2016-02-27T00:02:39.390127400Z" />
    <EventRecordID>1250</EventRecordID>
    <Channel>System</Channel>
  &nbs