Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 30/05/2023 9:18:05 PM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: DESKTOP-NTD2AI5
Description:
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
Windows.SecurityCenter.WscBrokerManager
and APPID
Unavailable
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="0">
</EventID>
<Version>
</Version>
<Level>
</Level>
<Task>
</Task>
<Opcode>
</Opcode>
<Keywords>
</Keywords>
<TimeCreated SystemTime="2023-05-30T17:18:05.3423442Z" />
<EventRecordID>
</EventRecordID>
<Correlation ActivityID="{80c82b5f-132c-4137-befb-44980b499644}" />
<Execution ProcessID="1036" ThreadID="1132" />
<Channel>
</Channel>
<Computer>
</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="param1">
</Data>
<Data Name="param2">
</Data>
<Data Name="param3">
</Data>
<Data Name="param4">
</Data>
<Data Name="param5">
</Data>
<Data Name="param6">
</Data>
<Data Name="param7">
</Data>
<Data Name="param8">
</Data>
<Data Name="param9">
</Data>
<Data Name="param10">
</Data>
<Data Name="param11">
</Data>
</EventData>
10016
0
3
0
0
0x8080000000000000
5235
System
DESKTOP-NTD2AI5
application-specific
Local
Launch
Windows.SecurityCenter.WscBrokerManager
Unavailable
NT AUTHORITY
SYSTEM
S-1-5-18
LocalHost (Using LRPC)
Unavailable
Unavailable
</Event>
The warnign above is a very common one ( 3 times in 5 sec) but for different programs
————————————————————————————————————————————————————-
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 30/05/2023 8:27:25 PM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: DESKTOP-NTD2AI5\Nitro_5
Computer: DESKTOP-NTD2AI5
Description:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-NTD2AI5\Nitro_5 SID (S-1-5-21-4120006448-3724438890-2172426716-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
10016
0
3
0
0
0x8080000000000000
4885
System
DESKTOP-NTD2AI5
application-specific
Local
Activation
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
DESKTOP-NTD2AI5
Nitro_5
S-1-5-21-4120006448-3724438890-2172426716-1001
LocalHost (Using LRPC)
Unavailable
Unavailable
——————————————————————————————————————————————————————————————————————
Log Name: System
Source: Netwtw08
Date: 30/05/2023 9:16:10 PM
Event ID: 6062
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: DESKTOP-NTD2AI5
Description:
6062 - Lso was triggered
Event Xml:
6062
0
3
0
0
0x80000000000000
5231
System
DESKTOP-NTD2AI5
\Device\NDMP1
Intel(R) Wireless-AC 9560 160MHz
000000000200300000000000AE170080000000000000000000000000000000000000000000000000
————————————————————————————————————————————————————————————————-
Log Name: System
Source: Microsoft-Windows-DNS-Client
Date: 30/05/2023 6:22:51 PM
Event ID: 1014
Task Category: (1014)
Level: Warning
Keywords: (268435456)
User: NETWORK SERVICE
Computer: DESKTOP-NTD2AI5
Description:
Name resolution for the name dns.msftncsi.com timed out after none of the configured DNS servers responded.
Event Xml:
1014
0
3
1014
0
0x4000000010000000
4604
System
DESKTOP-NTD2AI5
dns.msftncsi.com
16
02000035AC10005A0000000000000000
————————————————————————————————————————————————————————————————————————————-
Log Name: System
Source: Microsoft-Windows-DistributedCOM
Date: 30/05/2023 3:45:34 PM
Event ID: 10016
Task Category: None
Level: Warning
Keywords: Classic
User: DESKTOP-NTD2AI5\Nitro_5
Computer: DESKTOP-NTD2AI5
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
and APPID
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
to the user DESKTOP-NTD2AI5\Nitro_5 SID (S-1-5-21-4120006448-3724438890-2172426716-1001) from address LocalHost (Using LRPC) running in the application container Microsoft.Windows.ShellExperienceHost_10.0.19041.1949_neutral_neutral_cw5n1h2txyewy SID (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
<EventID Qualifiers="0">
</EventID>
<Version>
</Version>
<Level>
</Level>
<Task>
</Task>
<Opcode>
</Opcode>
<Keywords>
</Keywords>
<TimeCreated SystemTime="2023-05-30T11:45:34.1446579Z" />
<EventRecordID>
</EventRecordID>
<Correlation ActivityID="{39b04a84-6c4b-4d57-b71f-79523499e027}" />
<Execution ProcessID="1056" ThreadID="1464" />
<Channel>
</Channel>
<Computer>
</Computer>
<Security UserID="S-1-5-21-4120006448-3724438890-2172426716-1001" />
</System>
<EventData>
<Data Name="param1">
</Data>
<Data Name="param2">
</Data>
<Data Name="param3">
</Data>
<Data Name="param4">
</Data>
<Data Name="param5">
</Data>
<Data Name="param6">
</Data>
<Data Name="param7">
</Data>
<Data Name="param8">
</Data>
<Data Name="param9">
</Data>
<Data Name="param10">
</Data>
<Data Name="param11">
</Data>
</EventData>
10016
0
3
0
0
0x8080000000000000
4506
System
DESKTOP-NTD2AI5
machine-default
Local
Activation
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
DESKTOP-NTD2AI5
Nitro_5
S-1-5-21-4120006448-3724438890-2172426716-1001
LocalHost (Using LRPC)
Microsoft.Windows.ShellExperienceHost_10.0.19041.1949_neutral_neutral_cw5n1h2txyewy
S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708
</Event>
—————————————————————————————————————————————————————————————————
Log Name: System
Source: Microsoft-Windows-WLAN-AutoConfig
Date: 29/05/2023 8:43:48 PM
Event ID: 10002
Task Category: None
Level: Warning
Keywords:User: SYSTEM
Computer: DESKTOP-NTD2AI5
Description:
WLAN Extensibility Module has stopped.
Module Path: C:\Windows\system32\IntelIHVRouter08.dll
Event Xml:
10002
0
3
0
0
0x4000000000000000
4223
System
DESKTOP-NTD2AI5
C:\Windows\system32\IntelIHVRouter08.dll
—————————————————————————————————————————————————————————————————
Log Name: System
Source: Service Control Manager
Date: 29/05/2023 8:43:37 PM
Event ID: 7023
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DESKTOP-NTD2AI5
Description:
The vgc service terminated with the following error:
Incorrect function.
Event Xml:
7023
0
2
0
0
0x8080000000000000
4212
System
DESKTOP-NTD2AI5
vgc
%%1
7600670063000000
—————————————————————————————————————————————————————————————————
Log Name: System
Source: NetBT
Date: 29/05/2023 10:15:06 AM
Event ID: 4311
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: DESKTOP-NTD2AI5
Description:
Initialization failed because the driver device could not be created. Use the string "000000000100320000000000D71000C011010000250200C003000000000000000000000000000000" to identify the interface for which initialization failed. It represents the MAC address of the failed interface or the Globally Unique Interface Identifier (GUID) if NetBT was unable to map from GUID to MAC address. If neither the MAC address nor the GUID were available, the string represents a cluster device name.
Event Xml:
4311
0
2
0
0
0x80000000000000
3812
System
DESKTOP-NTD2AI5
000000000100320000000000D71000C011010000250200C003000000000000000000000000000000
—————————————————————————————————————————————————————————————————