Log Name: System
Source: volmgr
Date: 1/4/2025 1:29:08 AM
Event ID: 162
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Katie-PC
Description:
Dump file generation succeded.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="volmgr" />
<EventID Qualifiers="4">162</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2025-01-04T06:29:08.0843529Z" />
<EventRecordID>5338</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="428" />
<Channel>System</Channel>
<Computer>Katie-PC</Computer>
<Security />
</System>
<EventData>
<Data>\Device\HarddiskVolume3</Data>
<Binary>000000000100000000000000A2000400D90D00000000000000000000000000000000000000000000</Binary>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 1/4/2025 1:29:20 AM
Event ID: 1001
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: Katie-PC
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff80385513a7a, 0xffffdd8d8171e140, 0x0000000000000000). A dump was saved in: C:\WINDOWS\Minidump\010425-15343-01.dmp. Report Id: 767f8b65-626d-4ab0-8fe9-fcd2ee566b04.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{abce23e7-de45-4366-8631-84fa6c525952}" />
<EventID>1001</EventID>
<Version>1</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2025-01-04T06:29:20.5095639Z" />
<EventRecordID>5374</EventRecordID>
<Correlation />
<Execution ProcessID="1732" ThreadID="1736" />
<Channel>System</Channel>
<Computer>Katie-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="param1">0x0000003b (0x00000000c0000005, 0xfffff80385513a7a, 0xffffdd8d8171e140, 0x0000000000000000)</Data>
<Data Name="param2">C:\WINDOWS\Minidump\010425-15343-01.dmp</Data>
<Data Name="param3">767f8b65-626d-4ab0-8fe9-fcd2ee566b04</Data>
</EventData>
</Event>
Log Name: Security
Source: Microsoft-Windows-Eventlog
Date: 1/4/2025 1:29:20 AM
Event ID: 1101
Task Category: Event processing
Level: Error
Keywords: Audit Success
User: N/A
Computer: Katie-PC
Description:
Audit events have been dropped by the transport. 0
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Eventlog" Guid="{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}" />
<EventID>1101</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>101</Task>
<Opcode>0</Opcode>
<Keywords>0x4020000000000000</Keywords>
<TimeCreated SystemTime="2025-01-04T06:29:20.8798841Z" />
<EventRecordID>60608</EventRecordID>
<Correlation />
<Execution ProcessID="3244" ThreadID="3560" />
<Channel>Security</Channel>
<Computer>Katie-PC</Computer>
<Security />
</System>
<UserData>
<AuditEventsDropped xmlns="
http://manifests.microsoft.com/win/2004/08/windows/eventlog">
<Reason>0</Reason>
</AuditEventsDropped>
</UserData>
</Event>
Log Name: System
Source: EventLog
Date: 1/4/2025 1:29:20 AM
Event ID: 6008
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: Katie-PC
Description:
The previous system shutdown at 1:15:48 AM on ‎1/‎4/‎2025 was unexpected.
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2025-01-04T06:29:20.8825637Z" />
<EventRecordID>5326</EventRecordID>
<Correlation />
<Execution ProcessID="3244" ThreadID="3320" />
<Channel>System</Channel>
<Computer>Katie-PC</Computer>
<Security />
</System>
<EventData>
<Data>1:15:48 AM</Data>
<Data>‎1/‎4/‎2025</Data>
<Data>
</Data>
<Data>
</Data>
<Data>48015</Data>
<Data>
</Data>
<Data>
</Data>
<Binary>E90701000600040001000F003000B000E90701000600040006000F003000B000600900003C000000010000006009000001000000B00400000100000000000000</Binary>
</EventData>
</Event>
Log Name: System
Source: Microsoft-Windows-TPM-WMI
Date: 1/4/2025 1:31:21 AM
Event ID: 1796
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: Katie-PC
Description:
The Secure Boot update failed to update a Secure Boot variable with error The parameter is incorrect.. For more information, please see
https://go.microsoft.com/fwlink/?linkid=2169931
Event Xml:
<Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-TPM-WMI" Guid="{7d5387b0-cbe0-11da-a94d-0800200c9a66}" />
<EventID>1796</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2025-01-04T06:31:21.3856310Z" />
<EventRecordID>5424</EventRecordID>
<Correlation />
<Execution ProcessID="5692" ThreadID="2264" />
<Channel>System</Channel>
<Computer>Katie-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="HResult">-2147024809</Data>
</EventData>
</Event>