Код:

Log Name: Application
Source: Application Error
Date: 12/15/2008 1:26:30 PM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: User-PC
Description:
Faulting application EHShell.exe, version 6.0.6000.16386, time stamp 0x4549b55e, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000005, fault offset 0x00043387, process id 0x%9, application start time 0x%10.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Level>2</Level>
<Task>100</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-15T12:26:30.000Z" />
<EventRecordID>4285</EventRecordID>
<Channel>Application</Channel>
<Computer>User-PC</Computer>
<Security />
</System>
<EventData>
<Data>EHShell.exe</Data>
<Data>6.0.6000.16386</Data>
<Data>4549b55e</Data>
<Data>ntdll.dll</Data>
<Data>6.0.6001.18000</Data>
<Data>4791a7a6</Data>
<Data>c0000005</Data>
<Data>00043387</Data>
</EventData>
</Event>
Код:

Log Name: Application
Source: Microsoft-Windows-Search
Date: 12/15/2008 1:17:09 PM
Event ID: 3013
Task Category: Gatherer
Level: Error
Keywords: Classic
User: N/A
Computer: User-PC
Description:
The entry <C:\USERS\BARKASS\APPDATA\ROAMING\SOUNDGRAPH\TEMP\VERINFO.XML> in the hash map cannot be updated.
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
<EventID Qualifiers="49152">3013</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>3</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-15T12:17:09.000Z" />
<EventRecordID>4281</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>User-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="ExtraInfo">
Context: Application, SystemIndex Catalog
Details:
A device attached to the system is not functioning. (0x8007001f)
</Data>
<Data Name="Entry">C:\USERS\BARKASS\APPDATA\ROAMING\SOUNDGRAPH\TEMP\VERINFO.XML</Data>
</EventData>
</Event>
Код:

Log Name: Application
Source: Microsoft-Windows-WMI
Date: 12/15/2008 1:16:14 PM
Event ID: 10
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: User-PC
Description:
Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" EventSourceName="WinMgmt" />
<EventID Qualifiers="49152">10</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-15T12:16:14.000Z" />
<EventRecordID>4279</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>User-PC</Computer>
<Security />
</System>
<EventData>
<Data>//./root/CIMV2</Data>
<Data>SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99</Data>
<Data>0x80041003</Data>
</EventData>
</Event>
Код:

Log Name: Application
Source: VSS
Date: 12/14/2008 9:14:47 PM
Event ID: 8194
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: User-PC
Description:
Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {595f1288-67b5-4823-a6ff-d75e3913d792}
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="VSS" />
<EventID Qualifiers="0">8194</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-12-14T20:14:47.000Z" />
<EventRecordID>4222</EventRecordID>
<Channel>Application</Channel>
<Computer>User-PC</Computer>
<Security />
</System>
<EventData>
<Data>0x80070005</Data>
<Data>
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {595f1288-67b5-4823-a6ff-d75e3913d792}</Data>
<Binary>2D20436F64653A20575254575254494330303030313038382D2043616C6C3A20575254575254494330303030313035362D205049443A202030303030313531322D205449443A202030303030323832382D20434D443A2020433A5C57696E646F77735C73797374656D33325C737663686F73742E657865202D6B204E6574776F726B53657276696365202020202020202D20557365723A204E5420415554484F524954595C4E4554574F524B2053455256494345202020202D205369643A2020532D312D352D3230</Binary>
</EventData>
</Event>