Event[0]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:01.891
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?28T18:16:01.491044800Z.

Event[1]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:16:27.767
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:16:27.767
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[3]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[4]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[5]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[6]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A one-time boot sequence was used during this boot.

Event[7]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[8]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:16:01.891
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[9]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:05.688
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[10]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:05.689
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?07?-?15T20:27:07.000000000Z) has successfully loaded and registered with Filter Manager.

Event[11]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:16:06.336
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[12]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:07.178
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[13]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:16:07.936
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[14]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:16:07.939
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[15]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:16:07.939
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[16]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:16:07.940
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[17]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:08.301
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[18]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T12:16:08.326
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[19]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:16:08.673
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[20]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:16:09.094
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[21]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:16:09.206
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[22]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:16:09.225
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[23]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:09.354
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \SystemRoot\System32\config\DRIVERS was reorganized with a starting size of 5402624 bytes and an ending size of 5451776 bytes.

Event[24]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:10.211
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \SystemRoot\System32\Config\SOFTWARE was reorganized with a starting size of 61583360 bytes and an ending size of 61681664 bytes.

Event[25]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:10.233
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\DEFAULT was cleared updating 5 keys and creating 2 modified pages.

Event[26]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:13.854
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Default\NTUSER.DAT was cleared updating 12 keys and creating 4 modified pages.

Event[27]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T12:16:16.669
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[28]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:16.692
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\SECURITY was cleared updating 1 keys and creating 1 modified pages.

Event[29]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T12:16:16.761
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[30]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:16.763
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\SAM was cleared updating 1 keys and creating 1 modified pages.

Event[31]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T12:16:16.767
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[32]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:17.334
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the WlanSvc service was changed from demand start to auto start.

Event[33]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:16:17.582
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[34]:
  Log Name: System
  Source: Microsoft-Windows-SetupPlatform
  Date: 2017-01-28T12:16:26.401
  Event ID: 2005
  Task: Install Windows Task
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
New Setup information

Event[35]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-28T12:16:28.173
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[36]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:27.707
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\BBI was cleared updating 0 keys and creating 0 modified pages.

Event[37]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:27.736
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[38]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:27.739
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?07?-?15T20:27:16.000000000Z) has successfully loaded and registered with Filter Manager.

Event[39]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:27.741
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[40]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:16:27.743
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[41]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-28T12:16:27.844
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[42]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T12:16:27.848
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[43]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:16:28.138
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\AppCompat\Programs\Amcache.hve was cleared updating 0 keys and creating 0 modified pages.

Event[44]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:28.142
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The iphlpsvc service terminated with the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[45]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:28.205
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
CSC
dam

Event[46]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:29.911
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptcore.inf_amd64_513a957c36f5e600\lxptcore.inf for Device Instance ID PCI\VEN_8086&DEV_8C10&SUBSYS_85341043&REV_D4\3&11583659&0&E0 with the following status: 0x0.

Event[47]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:29.986
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Management Engine Interface 
Service File Name:  \SystemRoot\System32\drivers\HECIx64.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[48]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-28T12:16:30.033
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[49]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:30.036
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver heci.inf_amd64_76d37e15bbea3116\heci.inf for Device Instance ID PCI\VEN_8086&DEV_8C3A&SUBSYS_85341043&REV_04\3&11583659&0&B0 with the following status: 0x0.

Event[50]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:30.110
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver haswell.inf_amd64_1dc73fa0fbfffbdb\haswell.inf for Device Instance ID PCI\VEN_8086&DEV_0C00&SUBSYS_85341043&REV_06\3&11583659&0&00 with the following status: 0x0.

Event[51]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:30.160
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver e2414h.inf_amd64_963a890bd17b6fb1\e2414h.inf for Device Instance ID DISPLAY\DEL4091\1&8713BCA&0&UID0 with the following status: 0x0.

Event[52]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:30.221
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Kernel Debug Network Miniport (NDIS 6.20)
Service File Name:  \SystemRoot\System32\drivers\kdnic.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[53]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:30.241
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver kdnic.inf_amd64_e1703005cc16edf6\kdnic.inf for Device Instance ID ROOT\KDNIC\0000 with the following status: 0x0.

Event[54]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:31.080
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Service File Name:  \SystemRoot\system32\drivers\nvvad64v.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[55]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:31.085
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvvad_WaveExtensible for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0.

Event[56]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:31.236
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvvad.inf_amd64_f027e470fd029b8e\nvvad.inf for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0x0.

Event[57]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:31.236
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Synology Virtual USB Hub
Service File Name:  \SystemRoot\System32\drivers\busenum.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[58]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:31.259
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bus.inf_amd64_dd40146527c31848\bus.inf for Device Instance ID ROOT\USB\0000 with the following status: 0x0.

Event[59]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T12:16:31.389
  Event ID: 10000
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A driver package which uses user-mode driver framework version 2.19.0 is being installed on device ACPI\PNP0A0A\2&DABA3FF&2.

Event[60]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T12:16:31.389
  Event ID: 10001
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The UMDF service ASMBSW (CLSID {D44F49EC-2488-4542-A772-F358EF040213}) was installed.  It requires framework version 2.19.0 or higher.

Event[61]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T12:16:31.504
  Event ID: 10100
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver package installation has succeeded.

Event[62]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:31.564
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  AsIO
Service File Name:  SysWow64\drivers\AsIO.sys
Service Type:  kernel mode driver
Service Start Type:  system start
Service Account:  

Event[63]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:32.127
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  ASUS Com Service
Service File Name:  C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[64]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:35.789
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service WUDFRd for Device Instance ID ACPI\PNP0A0A\2&DABA3FF&2 with the following status: 0.

Event[65]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:35.829
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver asmbsw.inf_amd64_5f6fc21717202d29\asmbsw.inf for Device Instance ID ACPI\PNP0A0A\2&DABA3FF&2 with the following status: 0x0.

Event[66]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:35.846
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) PRO/1000 PCI Express Network Connection Driver I
Service File Name:  \SystemRoot\System32\drivers\e1i63x64.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[67]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:35.929
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver net1ic64.inf_amd64_5d49cc27a6d05e5c\net1ic64.inf for Device Instance ID PCI\VEN_8086&DEV_153B&SUBSYS_859F1043&REV_04\3&11583659&0&C8 with the following status: 0x0.

Event[68]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:35.955
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Streaming Quality Manager Proxy
Service File Name:  \SystemRoot\system32\DRIVERS\MSPQM.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[69]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:35.963
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service MSPQM for Device Instance ID SW\{DDF4358E-BB2C-11D0-A42F-00A0C9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196} with the following status: 0.

Event[70]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.230
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver ksfilter.inf_amd64_4b7251a1d691f0ad\ksfilter.inf for Device Instance ID SW\{DDF4358E-BB2C-11D0-A42F-00A0C9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196} with the following status: 0x0.

Event[71]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:36.237
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Streaming Clock Proxy
Service File Name:  \SystemRoot\system32\DRIVERS\MSPCLOCK.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[72]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.245
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service MSPCLOCK for Device Instance ID SW\{97EBAACC-95BD-11D0-A3EA-00A0C9223196}\{53172480-4791-11D0-A5D6-28DB04C10000} with the following status: 0.

Event[73]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.291
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver ksfilter.inf_amd64_4b7251a1d691f0ad\ksfilter.inf for Device Instance ID SW\{97EBAACC-95BD-11D0-A3EA-00A0C9223196}\{53172480-4791-11D0-A5D6-28DB04C10000} with the following status: 0x0.

Event[74]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:36.299
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Streaming Service Proxy
Service File Name:  \SystemRoot\system32\DRIVERS\MSKSSRV.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[75]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.306
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service MSKSSRV for Device Instance ID SW\{96E080C7-143C-11D1-B40F-00A0C9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196} with the following status: 0.

Event[76]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.351
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver ksfilter.inf_amd64_4b7251a1d691f0ad\ksfilter.inf for Device Instance ID SW\{96E080C7-143C-11D1-B40F-00A0C9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196} with the following status: 0x0.

Event[77]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:36.362
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Streaming Tee/Sink-to-Sink Converter
Service File Name:  \SystemRoot\system32\DRIVERS\MSTEE.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[78]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.367
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service MSTEE for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196} with the following status: 0.

Event[79]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.412
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver ksfilter.inf_amd64_4b7251a1d691f0ad\ksfilter.inf for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196} with the following status: 0x0.

Event[80]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:36.487
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Trusted Audio Drivers
Service File Name:  \SystemRoot\system32\DRIVERS\drmkaud.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[81]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.488
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service drmkaud for Device Instance ID SW\{EEC12DB6-AD9C-4168-8658-B03DAEF417FE}\{ABD61E00-9350-47E2-A632-4438B90C6641} with the following status: 0.

Event[82]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.598
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver wdmaudio.inf_amd64_bf7ec511830b3442\wdmaudio.inf for Device Instance ID SW\{EEC12DB6-AD9C-4168-8658-B03DAEF417FE}\{ABD61E00-9350-47E2-A632-4438B90C6641} with the following status: 0x0.

Event[83]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.617
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptsmb.inf_amd64_71d6f67e09383c9e\lxptsmb.inf for Device Instance ID PCI\VEN_8086&DEV_8C22&SUBSYS_85341043&REV_04\3&11583659&0&FB with the following status: 0x0.

Event[84]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:36.664
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptcore.inf_amd64_513a957c36f5e600\lxptcore.inf for Device Instance ID PCI\VEN_8086&DEV_8C44&SUBSYS_85341043&REV_04\3&11583659&0&F8 with the following status: 0x0.

Event[85]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-28T12:16:39.128
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[86]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.021
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptcore.inf_amd64_513a957c36f5e600\lxptcore.inf for Device Instance ID PCI\VEN_8086&DEV_8C12&SUBSYS_85341043&REV_D4\3&11583659&0&E1 with the following status: 0x0.

Event[87]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.176
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptusb.inf_amd64_917a5726857a25a6\lxptusb.inf for Device Instance ID PCI\VEN_8086&DEV_8C2D&SUBSYS_85341043&REV_04\3&11583659&0&D0 with the following status: 0x0.

Event[88]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.471
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver haswell.inf_amd64_1dc73fa0fbfffbdb\haswell.inf for Device Instance ID PCI\VEN_8086&DEV_0C01&SUBSYS_85341043&REV_06\3&11583659&0&08 with the following status: 0x0.

Event[89]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.491
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service MSTEE for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000} with the following status: 0.

Event[90]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.535
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver ksfilter.inf_amd64_4b7251a1d691f0ad\ksfilter.inf for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000} with the following status: 0x0.

Event[91]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:40.666
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptusb.inf_amd64_917a5726857a25a6\lxptusb.inf for Device Instance ID PCI\VEN_8086&DEV_8C26&SUBSYS_85341043&REV_04\3&11583659&0&E8 with the following status: 0x0.

Event[92]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:45.740
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lxptcore.inf_amd64_513a957c36f5e600\lxptcore.inf for Device Instance ID PCI\VEN_8086&DEV_8C16&SUBSYS_85341043&REV_D4\3&11583659&0&E3 with the following status: 0x0.

Event[93]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:50.909
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  nvlddmkm
Service File Name:  \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3f929cc119e3b994\nvlddmkm.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[94]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:50.919
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[95]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:58.210
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_3f929cc119e3b994\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[96]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:16:58.582
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Service for NVIDIA High Definition Audio Driver
Service File Name:  \SystemRoot\system32\drivers\nvhda64v.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[97]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:58.597
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0001 with the following status: 0.

Event[98]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:16:58.817
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0001 with the following status: 0x0.

Event[99]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:01.583
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Service for Realtek HD Audio (WDM)
Service File Name:  \SystemRoot\system32\drivers\RTKVHD64.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[100]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:01.597
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service IntcAzAudAddService for Device Instance ID HDAUDIO\FUNC_01&VEN_10EC&DEV_0900&SUBSYS_1043855F&REV_1000\4&31483CB2&0&0001 with the following status: 0.

Event[101]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:02.051
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  DTSAudioSvc
Service File Name:  "C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[102]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:02.051
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the DTSAudioSvc service was changed from demand start to auto start.

Event[103]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:02.294
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver hdxrt.inf_amd64_d793fae5275e9b3d\hdxrt.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10EC&DEV_0900&SUBSYS_1043855F&REV_1000\4&31483CB2&0&0001 with the following status: 0x0.

Event[104]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:02.501
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0101 with the following status: 0.

Event[105]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:02.707
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0101 with the following status: 0x0.

Event[106]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:02.869
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0201 with the following status: 0.

Event[107]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.066
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0201 with the following status: 0x0.

Event[108]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.230
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0301 with the following status: 0.

Event[109]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.425
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0301 with the following status: 0x0.

Event[110]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:03.551
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth RAM Firmware Download USB Filter
Service File Name:  \SystemRoot\system32\drivers\bcbtums.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[111]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.555
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service bcbtums for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[112]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:03.551
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Driver Management Service
Service File Name:  %SystemRoot%\system32\BtwRSupportService.exe
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[113]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.578
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BcmBtRSupport for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[114]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:03.567
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  btwampfl
Service File Name:  \SystemRoot\system32\DRIVERS\btwampfl.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[115]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.580
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service btwampfl for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[116]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:03.567
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Radio USB Driver
Service File Name:  \SystemRoot\system32\DRIVERS\BTHUSB.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[117]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.584
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BTHUSB for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[118]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:03.583
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Port Driver
Service File Name:  \SystemRoot\system32\DRIVERS\BTHport.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[119]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.597
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BTHPORT for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[120]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:03.822
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bcbtums-win8x64-brcm.inf_amd64_1e9ff3aabe732c02\bcbtums-win8x64-brcm.inf for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0x0.

Event[121]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:03.807
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[122]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[123]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[124]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[125]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[126]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[127]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[128]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:17:04.010
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[129]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:04.229
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Broadcom 802.11 Network Adapter Driver
Service File Name:  \SystemRoot\system32\DRIVERS\bcmwl664.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[130]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:04.242
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BCM43XX for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0.

Event[131]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:04.243
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service vwifibus for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0.

Event[132]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:04.696
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bcmwl6.inf_amd64_058661040649fb3e\bcmwl6.inf for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0x0.

Event[133]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:17:04.697
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[134]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:04.901
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Realtek RT640 NT Driver
Service File Name:  \SystemRoot\System32\drivers\rt640x64.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[135]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:04.996
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver rt640x64.inf_amd64_e334a4b7b7769300\rt640x64.inf for Device Instance ID PCI\VEN_10EC&DEV_8168&SUBSYS_859E1043&REV_11\6&EB089EB&0&002800E3 with the following status: 0x0.

Event[136]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:05.042
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Low Energy Driver
Service File Name:  \SystemRoot\system32\DRIVERS\BthLEEnum.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[137]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.056
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BthLEEnum for Device Instance ID BTH\MS_BTHLE\7&159F4D6&0&0 with the following status: 0.

Event[138]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.068
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bthleenum.inf_amd64_a274b2812788ef00\bthleenum.inf for Device Instance ID BTH\MS_BTHLE\7&159F4D6&0&0 with the following status: 0x0.

Event[139]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:05.073
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Device (RFCOMM Protocol TDI)
Service File Name:  \SystemRoot\System32\drivers\rfcomm.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[140]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:05.073
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Enumerator Service
Service File Name:  \SystemRoot\System32\drivers\BthEnum.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[141]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.167
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver tdibth.inf_amd64_e08dea69c9fe18b8\tdibth.inf for Device Instance ID BTH\MS_RFCOMM\7&159F4D6&0&0 with the following status: 0x0.

Event[142]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.192
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BthEnum for Device Instance ID BTH\MS_BTHBRB\7&159F4D6&0&1 with the following status: 0.

Event[143]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.199
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bth.inf_amd64_0ed9858b9b899077\bth.inf for Device Instance ID BTH\MS_BTHBRB\7&159F4D6&0&1 with the following status: 0x0.

Event[144]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:05.198
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Bluetooth Device (Personal Area Network)
Service File Name:  \SystemRoot\System32\drivers\bthpan.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[145]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:17:05.227
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bthpan.inf_amd64_9c55541e4907e74e\bthpan.inf for Device Instance ID BTH\MS_BTHPAN\7&159F4D6&0&2 with the following status: 0x0.

Event[146]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.598
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.AAD.BrokerPlugin_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[147]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.695
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.AccountsControl_10.0.14393.0_neutral__cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[148]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.765
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BioEnrollment_10.0.14393.0_neutral__cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[149]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.828
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.LockApp_10.0.14393.0_neutral__cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[150]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.917
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[151]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:05.987
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.PPIProjection_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[152]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.050
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Apprep.ChxApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[153]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.112
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.AssignedAccessLockApp_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[154]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.188
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.CloudExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[155]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.260
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ContentDeliveryManager_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[156]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.421
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[157]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.501
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ParentalControls_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[158]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.562
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.SecondaryTileExperience_10.0.0.0_neutral__cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[159]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.645
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.SecureAssessmentBrowser_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[160]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.725
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[161]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.796
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxGameCallableUI_1000.14393.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[162]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.902
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Windows.ContactSupport_10.0.14393.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[163]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:06.967
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[164]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:07.028
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Windows.MiracastView_6.3.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[165]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:07.091
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Windows.PrintDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[166]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:07.955
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.3DBuilder_11.0.47.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[167]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:08.048
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Advertising.Xaml_10.0.1605.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[168]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:08.122
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Advertising.Xaml_10.0.1605.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[169]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:08.706
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BingWeather_4.9.51.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[170]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:08.896
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.0.1471.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[171]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:09.276
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Getstarted_3.11.3.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[172]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:09.645
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Messaging_3.19.1001.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[173]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:10.165
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftOfficeHub_17.6801.23751.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[174]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:11.838
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftSolitaireCollection_3.9.5100.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[175]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:12.190
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_1.0.136.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[176]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:13.447
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Office.OneNote_17.6868.57981.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[177]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:13.750
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.OneConnect_1.1605.17.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[178]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:14.112
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.People_10.0.11902.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[179]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:15.462
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.4.86.0_x64__kzf8qxf38zg5c\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[180]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:15.609
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.StorePurchaseApp_1.0.45.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[181]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:16.320
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Photos_16.511.8780.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[182]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:16.773
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1605.1742.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[183]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:17.109
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsCalculator_10.1605.1582.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[184]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:17.451
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsCamera_2016.404.190.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[185]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:19.711
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\microsoft.windowscommunicationsapps_17.6868.41201.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[186]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:20.195
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsFeedbackHub_1.3.1741.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[187]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:21.077
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsMaps_5.1603.1830.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[188]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:21.437
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsSoundRecorder_10.1605.1622.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[189]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:21.994
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11606.1001.39.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[190]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:22.718
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxApp_15.18.23005.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[191]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:22.880
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxIdentityProvider_11.18.16009.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[192]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:23.560
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ZuneMusic_3.6.19261.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[193]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:24.179
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ZuneVideo_3.6.19281.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[194]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:25.053
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\C:\WINDOWS\System32\config\COMPONENTS was reorganized with a starting size of 33079296 bytes and an ending size of 33067008 bytes.

Event[195]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:25.168
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Message Queuing service was changed from demand start to auto start.

Event[196]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:31.685
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Net.Tcp Port Sharing Service service was changed from disabled to demand start.

Event[197]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:31.685
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Net.Tcp Listener Adapter service was changed from disabled to auto start.

Event[198]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:33.169
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Net.Msmq Listener Adapter service was changed from disabled to auto start.

Event[199]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:17:36.451
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Net.Pipe Listener Adapter service was changed from disabled to auto start.

Event[200]:
  Log Name: System
  Source: Microsoft-Windows-Setup
  Date: 2017-01-28T12:17:38.849
  Event ID: 2004
  Task: OS information
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Successfully logged OS information

Event[201]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:39.248
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\C:\WINDOWS\System32\SMI\Store\Machine\SCHEMA.DAT was reorganized with a starting size of 11878400 bytes and an ending size of 11825152 bytes.

Event[202]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:39.271
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\system32\config\elam was cleared updating 0 keys and creating 0 modified pages.

Event[203]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:43.870
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Windows.old\WINDOWS\system32\config\userdiff was cleared updating 1 keys and creating 1 modified pages.

Event[204]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:17:43.884
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Windows.old\Users\Default\NTUSER.DAT was cleared updating 1 keys and creating 1 modified pages.

Event[205]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:18:01.156
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Network List Service service terminated with the following error: 
The device is not ready.

Event[206]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:18:27.938
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver printqueue.inf_amd64_293dcb0d10d72f40\printqueue.inf for Device Instance ID SWD\PRINTENUM\PRINTQUEUES with the following status: 0x0.

Event[207]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:18:28.330
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Printer Extensions and Notifications
Service File Name:  %SystemRoot%\system32\svchost.exe -k print
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[208]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:18:28.330
  Event ID: 7030
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Printer Extensions and Notifications service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Event[209]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:19:58.761
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Device Association Service service was changed from demand start to auto start.

Event[210]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.276
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) PROSet Monitoring Service
Service File Name:  C:\Windows\system32\IProsetMonitor.exe
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[211]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.276
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  TeamViewer 11
Service File Name:  "C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[212]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  PAExec
Service File Name:  C:\WINDOWS\PAExec.exe -service
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[213]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7030
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The PAExec service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Event[214]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Office Groove Audit Service
Service File Name:  "C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[215]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Display Container LS
Service File Name:  "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[216]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Management and Security Application Local Management Service
Service File Name:  "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[217]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.292
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Wireless Controller Service
Service File Name:  "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[218]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  TechSmith Uploader Service
Service File Name:  "C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe" /service
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[219]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Capability Licensing Service Interface
Service File Name:  "C:\Program Files\Intel\iCLS Client\HeciServer.exe"
Service Type:  user mode service
Service Start Type:  disabled
Service Account:  LocalSystem

Event[220]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Office Diagnostics Service
Service File Name:  "C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[221]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA LocalSystem Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[222]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA NetworkService Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[223]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.308
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Epson Scanner Service
Service File Name:  C:\WINDOWS\system32\EscSvc64.exe
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[224]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  EpsonCustomerResearchParticipation
Service File Name:  "C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[225]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Office Source Engine
Service File Name:  "C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[226]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Dynamic Application Loader Host Interface Service
Service File Name:  "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[227]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Adobe Acrobat Update Service
Service File Name:  "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[228]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Google Update Service (gupdate)
Service File Name:  "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[229]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Google Update Service (gupdatem)
Service File Name:  "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[230]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  UsbClientService
Service File Name:  C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
Service Type:  user mode service
Service Start Type:  disabled
Service Account:  LocalSystem

Event[231]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.323
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Adobe Flash Player Update Service
Service File Name:  C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[232]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  EpsonBidirectionalService
Service File Name:  C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
Service Type:  user mode service
Service Start Type:  disabled
Service Account:  LocalSystem

Event[233]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Skype Updater
Service File Name:  "C:\Program Files (x86)\Skype\Updater\Updater.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[234]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Update Manager
Service File Name:  "C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe"
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[235]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) Capability Licensing Service TCP IP Interface
Service File Name:  "C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe"
Service Type:  user mode service
Service Start Type:  disabled
Service Account:  LocalSystem

Event[236]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  UltraMon Utility Driver
Service File Name:  \??\C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys
Service Type:  kernel mode driver
Service Start Type:  auto start
Service Account:  

Event[237]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  megasas2i
Service File Name:  \SystemRoot\System32\drivers\MegaSas2i.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[238]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Acronis Storage Filter Management
Service File Name:  \SystemRoot\system32\DRIVERS\fltsrv.sys
Service Type:  kernel mode driver
Service Start Type:  boot start
Service Account:  

Event[239]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.339
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA KMS
Service File Name:  \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[240]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.433
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[241]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.433
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[242]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.433
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[243]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[244]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[245]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[246]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[247]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[248]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[249]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[250]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[251]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[252]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[253]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[254]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[255]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.448
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[256]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[257]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[258]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[259]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[260]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[261]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[262]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.464
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[263]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[264]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[265]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[266]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[267]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[268]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[269]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[270]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[271]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[272]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[273]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[274]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[275]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[276]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[277]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[278]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[279]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[280]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[281]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[282]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[283]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.480
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[284]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[285]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[286]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[287]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[288]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[289]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[290]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[291]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.495
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[292]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.511
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[293]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.511
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[294]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.511
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[295]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.511
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[296]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[297]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[298]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[299]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[300]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[301]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[302]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[303]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.526
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[304]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[305]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[306]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[307]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[308]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[309]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[310]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[311]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[312]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[313]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[314]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[315]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.542
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[316]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.573
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[317]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.573
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[318]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.573
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[319]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.573
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[320]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[321]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[322]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[323]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[324]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[325]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[326]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[327]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[328]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[329]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[330]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[331]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[332]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[333]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[334]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[335]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[336]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[337]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[338]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[339]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[340]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.589
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[341]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.605
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[342]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.605
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[343]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.605
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[344]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[345]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[346]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[347]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[348]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[349]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.620
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[350]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[351]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[352]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[353]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[354]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[355]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[356]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.636
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[357]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[358]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[359]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[360]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[361]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[362]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[363]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[364]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[365]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[366]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.651
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[367]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[368]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[369]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[370]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[371]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[372]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[373]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.667
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[374]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[375]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[376]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[377]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[378]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[379]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.683
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[380]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[381]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[382]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[383]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[384]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[385]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[386]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[387]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[388]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.698
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[389]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[390]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[391]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[392]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[393]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[394]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[395]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[396]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[397]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[398]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[399]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[400]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[401]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[402]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.714
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[403]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[404]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[405]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[406]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[407]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[408]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[409]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[410]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[411]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[412]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[413]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[414]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[415]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[416]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[417]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.730
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[418]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.761
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[419]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.761
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[420]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.761
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[421]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:00.761
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[422]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:20:01.167
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout.

Event[423]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:20:01.167
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout.

Event[424]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:01.167
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Network List Service service terminated with the following error: 
The device is not ready.

Event[425]:
  Log Name: System
  Source: Microsoft-Windows-Bits-Client
  Date: 2017-01-28T12:20:03.245
  Event ID: 16392
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The BITS service failed to start.  Error 0x80080005.

Event[426]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:03.245
  Event ID: 7024
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Background Intelligent Transfer Service service terminated with the following service-specific error: 
Server execution failed

Event[427]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:20:14.090
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[428]:
  Log Name: System
  Source: User32
  Date: 2017-01-28T12:20:13.668
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The process C:\WINDOWS\system32\winlogon.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned)
 Reason Code: 0x80020003
 Shutdown Type: restart
 Comment: 

Event[429]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T12:20:14.099
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[430]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:20:14.204
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[431]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:20:14.206
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[432]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:20:42.829
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[433]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:20:42.829
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[434]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:20:42.829
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 12 seconds.

Event[435]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T12:20:19.062
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[436]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:20:19.291
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?28T18:20:19.291864900Z.

Event[437]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:20:30.649
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?28T18:20:30.495194700Z.

Event[438]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[439]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[440]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[441]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[442]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A one-time boot sequence was used during this boot.

Event[443]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[444]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T12:20:30.650
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[445]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:34.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[446]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:34.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?07?-?15T20:27:07.000000000Z) has successfully loaded and registered with Filter Manager.

Event[447]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:20:34.802
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[448]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:34.833
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[449]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:34.890
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[450]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T12:20:34.910
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[451]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:20:35.260
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[452]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:20:35.681
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[453]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:20:35.787
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[454]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T12:20:35.807
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[455]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T12:20:36.316
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[456]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-28T12:20:36.316
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[457]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-28T12:20:36.490
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[458]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:20:36.845
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[459]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:20:36.848
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[460]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:20:36.848
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[461]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T12:20:36.849
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[462]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:37.301
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[463]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T12:20:38.662
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[464]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T12:20:38.754
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[465]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T12:20:38.760
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[466]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-28T12:20:39.655
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[467]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-28T12:20:43.512
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[468]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:42.811
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[469]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:42.814
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?07?-?15T20:27:16.000000000Z) has successfully loaded and registered with Filter Manager.

Event[470]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:42.817
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[471]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:20:42.820
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[472]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-28T12:20:42.841
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[473]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T12:20:42.850
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[474]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[475]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[476]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[477]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[478]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[479]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[480]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T12:20:42.871
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[481]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:20:42.902
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\system32\config\elam was cleared updating 0 keys and creating 0 modified pages.

Event[482]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:20:43.166
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[483]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:20:43.237
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[484]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:43.418
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[485]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:43.903
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Browser service depends on the LanmanWorkstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[486]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:44.387
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Virtual WiFi Miniport Service
Service File Name:  \SystemRoot\System32\drivers\vwifimp.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[487]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:44.387
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[488]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:20:44.402
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver netvwifimp.inf_amd64_389d3e2956b38173\netvwifimp.inf for Device Instance ID {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_SAP\7&1353AC59&0&11 with the following status: 0x0.

Event[489]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:44.403
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft Tunnel Miniport Adapter Driver
Service File Name:  \SystemRoot\System32\drivers\tunnel.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[490]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:20:44.422
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nettun.inf_amd64_e492882a4d9613a4\nettun.inf for Device Instance ID SWD\IP_TUNNEL_VBUS\ISATAP_0 with the following status: 0x0.

Event[491]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:45.465
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[492]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:45.465
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[493]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:45.465
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[494]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-01-28T12:20:45.639
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[495]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:20:46.300
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver digitalmediadevice.inf_amd64_4752f8af9cd0a4d7\digitalmediadevice.inf for Device Instance ID SWD\DAFUPNPPROVIDER\UUID:0C845881-00D2-1000-BB52-90F1AAA3A437 with the following status: 0x0.

Event[496]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T12:20:46.660
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nettun.inf_amd64_e492882a4d9613a4\nettun.inf for Device Instance ID SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE with the following status: 0x0.

Event[497]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:46.840
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[498]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:46.840
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[499]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:46.840
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[500]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:47.887
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[501]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:47.887
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[502]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:47.887
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[503]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:51.184
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Distributed Transaction Coordinator service was changed from demand start to auto start.

Event[504]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:20:51.356
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Distributed Transaction Coordinator service was changed from auto start to demand start.

Event[505]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:21:34.145
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[506]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:21:34.152
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[507]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:40.857
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Task Scheduler service was changed from disabled to demand start.

Event[508]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.077
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec.

Event[509]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:41.092
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Task Scheduler service was changed from demand start to disabled.

Event[510]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.193
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[511]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.198
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[512]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.222
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[513]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.233
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan definition. Additional Data: Error Value: C:\Program Files\Microsoft Security Client\MpCmdRun.exe.

Event[514]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.242
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[515]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.247
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task definition. Additional Data: Error Value: C:\Users\Roberto\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe.

Event[516]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.258
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[517]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.259
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[518]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.263
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[519]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.267
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[520]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.289
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe.

Event[521]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.293
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[522]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.303
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[523]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.324
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[524]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.325
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[525]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.354
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task v2 definition. Additional Data: Error Value: %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe.

Event[526]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.371
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[527]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.382
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[528]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.459
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[529]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.478
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[530]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.491
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[531]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.513
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[532]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.520
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[533]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T12:21:41.532
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[534]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:41.545
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Distributed Transaction Coordinator service was changed from demand start to auto start.

Event[535]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:43.014
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Distributed Transaction Coordinator service was changed from auto start to demand start.

Event[536]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:44.107
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[537]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:44.107
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[538]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:44.107
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[539]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:21:44.128
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[540]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T12:21:44.142
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[541]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.748
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[542]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.748
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[543]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.748
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[544]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.889
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[545]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.889
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[546]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:46.889
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[547]:
  Log Name: System
  Source: Microsoft-Windows-WinRM
  Date: 2017-01-28T12:21:50.092
  Event ID: 10142
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WinRM service cannot migrate the listener with Address * and Transport HTTP. A listener that has the same Address and Transport configuration already exists.

Event[548]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-28T12:21:50.092
  Event ID: 15008
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:5985/wsman/ was successfully deleted.

Event[549]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-28T12:21:50.092
  Event ID: 15007
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:5985/wsman/ was successfully added.

Event[550]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:50.717
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.3DBuilder_12.0.3131.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[551]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.857
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[552]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.857
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[553]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.857
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[554]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.982
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[555]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.982
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[556]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:50.982
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[557]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:50.985
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Advertising.Xaml_10.1611.3.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[558]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.076
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[559]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.076
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[560]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.076
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[561]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.217
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[562]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.217
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[563]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.217
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[564]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:51.223
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Advertising.Xaml_10.1611.3.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[565]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.311
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[566]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.311
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[567]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.311
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[568]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.420
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[569]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.420
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[570]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:51.420
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[571]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:51.427
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[572]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:51.901
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BingFinance_4.18.37.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[573]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:52.301
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BingNews_4.18.41.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[574]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:52.695
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BingSports_4.18.37.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[575]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:53.275
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[576]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:53.574
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.CommsPhone_1.10.15000.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[577]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:53.756
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ConnectivityStore_1.1604.4.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[578]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:53.943
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.DesktopAppInstaller_1.0.2181.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[579]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:54.124
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Getstarted_4.4.11.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[580]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:54.741
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftOfficeHub_17.7608.23501.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[581]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.014
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[582]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.014
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[583]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.014
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[584]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.139
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[585]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.139
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[586]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:21:56.139
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Computer Browser service depends on the Workstation service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[587]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:57.332
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftSolitaireCollection_3.12.12200.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[588]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:57.530
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.MicrosoftStickyNotes_1.4.7.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[589]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:58.899
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Office.OneNote_17.7766.57771.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[590]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:59.106
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Office.Sway_17.7766.45161.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[591]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:59.471
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.OneConnect_1.1607.6.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[592]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:59.629
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.People_10.1.3410.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[593]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:59.826
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Services.Store.Engagement_10.0.1610.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[594]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:21:59.902
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Services.Store.Engagement_10.0.1610.0_x86__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[595]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:00.103
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.10.152.0_x64__kzf8qxf38zg5c\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[596]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:00.231
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.StorePurchaseApp_11608.1000.2431.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[597]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:00.808
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[598]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:01.059
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsAlarms_10.1701.10103.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[599]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:01.342
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsCalculator_10.1701.10102.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[600]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:01.711
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsCamera_2016.1101.20.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[601]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:01.930
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\microsoft.windowscommunicationsapps_17.7812.42257.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[602]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:02.430
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsDVDPlayer_3.6.13291.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[603]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:02.926
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsFeedbackHub_1.1611.3471.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[604]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:04.094
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsMaps_5.1611.3342.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[605]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:04.510
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsPhone_10.1609.2561.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[606]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:04.671
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsSoundRecorder_10.1701.10102.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[607]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:04.904
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsStore_11610.1001.25.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[608]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:05.176
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxApp_24.25.26002.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[609]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:05.320
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.XboxIdentityProvider_11.19.19003.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[610]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:05.539
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ZuneMusic_10.16122.10271.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[611]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:06.124
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ZuneVideo_10.16112.10221.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[612]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:06.506
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\9E2F88E3.Twitter_5.4.1.0_x86__wgeqdkkx372wm\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[613]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:15.367
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\king.com.CandyCrushSodaSaga_1.81.900.0_x86__kgqvnymyfvs32\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[614]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:18.143
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\system32\config\elam was cleared updating 0 keys and creating 0 modified pages.

Event[615]:
  Log Name: System
  Source: Microsoft-Windows-UserModePowerService
  Date: 2017-01-28T12:22:18.197
  Event ID: 22
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Reapply power settings upon completion of the provisioning engine's turn 1

Event[616]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T12:22:29.646
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[617]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:22:30.261
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\system32\Config\Elam was cleared updating 0 keys and creating 0 modified pages.

Event[618]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:22:30.420
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[619]:
  Log Name: System
  Source: NETLOGON
  Date: 2017-01-28T12:22:40.811
  Event ID: 3095
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration.

Event[620]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:22:44.873
  Event ID: 7024
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The BranchCache service terminated with the following service-specific error: 
This program is blocked by group policy. For more information, contact your system administrator.

Event[621]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:22:47.170
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Biometric Service service was changed from demand start to auto start.

Event[622]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:22:48.873
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[623]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-28T12:22:59.295
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[624]:
  Log Name: System
  Source: Microsoft-Windows-GroupPolicy
  Date: 2017-01-28T12:22:59.411
  Event ID: 1502
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Group Policy settings for the computer were processed successfully. New settings from 1 Group Policy objects were detected and applied.

Event[625]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T12:22:59.623
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[626]:
  Log Name: System
  Source: Microsoft-Windows-GroupPolicy
  Date: 2017-01-28T12:22:59.803
  Event ID: 1501
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy.

Event[627]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:22:59.967
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[628]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:22:59.967
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[629]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:03.078
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat was cleared updating 4 keys and creating 1 modified pages.

Event[630]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:03.210
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[631]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:03.334
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages.

Event[632]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:04.161
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[633]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:04.316
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[634]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:04.814
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[635]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:04.841
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[636]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:04.965
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.PPIProjection_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[637]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.020
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[638]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.112
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[639]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.228
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[640]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.334
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.SecondaryTileExperience_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[641]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.441
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[642]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.547
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[643]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.675
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Windows.ContactSupport_cw5n1h2txyewy\Settings\settings.dat was cleared updating 2 keys and creating 1 modified pages.

Event[644]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.787
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Windows.MiracastView_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[645]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:05.856
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[646]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:07.152
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 2 keys and creating 1 modified pages.

Event[647]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:07.457
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[648]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:07.553
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[649]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:07.926
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[650]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:08.025
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[651]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:08.357
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 2 keys and creating 1 modified pages.

Event[652]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T12:23:08.558
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[653]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:24:20.721
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[654]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:26:20.721
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[655]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T12:27:03.136
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[656]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T12:27:31.374
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[657]:
  Log Name: System
  Source: User32
  Date: 2017-01-28T12:28:38.479
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[658]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T12:28:44.176
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[659]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T12:28:59.296
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[660]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T12:28:59.291
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[661]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:03:31.401
  Event ID: 6008
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The previous system shutdown at 12:55:46 PM on ?1/?28/?2017 was unexpected.

Event[662]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:03:31.401
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[663]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:03:31.401
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[664]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:03:31.401
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[665]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:03:24.660
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?28T19:03:24.495070900Z.

Event[666]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[667]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[668]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[669]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[670]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A one-time boot sequence was used during this boot.

Event[671]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[672]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:03:24.660
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[673]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:28.414
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[674]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:28.415
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?07?-?15T20:27:07.000000000Z) has successfully loaded and registered with Filter Manager.

Event[675]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:28.415
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[676]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:03:28.795
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[677]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:28.827
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[678]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:28.885
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[679]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T13:03:28.905
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Event[680]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T13:03:28.906
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[681]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:03:29.231
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[682]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:03:29.610
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[683]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:03:29.715
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[684]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:03:29.735
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[685]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T13:03:30.043
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[686]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-28T13:03:30.043
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[687]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-28T13:03:30.193
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[688]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:03:30.548
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[689]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:03:30.551
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[690]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:03:30.551
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[691]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:03:30.552
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[692]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T13:03:31.035
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[693]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T13:03:31.132
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[694]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T13:03:31.138
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[695]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.260
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[696]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:31.382
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[697]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:31.385
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?07?-?15T20:27:16.000000000Z) has successfully loaded and registered with Filter Manager.

Event[698]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:31.387
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[699]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:03:31.390
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[700]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-28T13:03:31.430
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[701]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[702]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[703]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[704]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[705]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[706]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[707]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:03:31.432
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[708]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T13:03:31.442
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[709]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.568
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec.

Event[710]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.652
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[711]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.654
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[712]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.663
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[713]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.666
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan definition. Additional Data: Error Value: C:\Program Files\Microsoft Security Client\MpCmdRun.exe.

Event[714]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.669
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[715]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.672
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task definition. Additional Data: Error Value: C:\Users\Roberto\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe.

Event[716]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.681
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[717]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.682
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[718]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.683
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[719]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.684
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[720]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.688
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe.

Event[721]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.689
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[722]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.692
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[723]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:31.684
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[724]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:31.684
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[725]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.700
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[726]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.701
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[727]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.710
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task v2 definition. Additional Data: Error Value: %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe.

Event[728]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.721
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[729]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.724
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[730]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.756
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[731]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.763
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[732]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.773
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[733]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.780
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[734]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.782
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[735]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:03:31.786
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[736]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T13:03:32.257
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[737]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-28T13:03:33.894
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[738]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-28T13:03:34.257
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[739]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-28T13:03:34.268
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[740]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:03:33.774
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[741]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-28T13:03:33.835
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[742]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:03:33.856
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[743]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:03:33.927
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[744]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-28T13:03:33.981
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[745]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:03:34.265
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[746]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:34.267
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[747]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:03:34.268
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[748]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:03:34.421
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[749]:
  Log Name: System
  Source: Microsoft-Windows-StartupRepair
  Date: 2017-01-28T13:03:34.824
  Event ID: 1002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Startup Repair failed.

Event[750]:
  Log Name: System
  Source: Microsoft-Windows-StartupRepair
  Date: 2017-01-28T13:03:34.824
  Event ID: 1116
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows could not detect the problem. The boot status indicated that Windows booted successfully.

Event[751]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:34.874
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver haswell.inf_amd64_1dc73fa0fbfffbdb\haswell.inf for Device Instance ID PCI\VEN_8086&DEV_0C05&SUBSYS_85341043&REV_06\3&11583659&0&09 with the following status: 0x0.

Event[752]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:35.696
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[753]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:35.698
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[754]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T13:03:41.062
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[755]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:42.646
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&8F1C284&0&0009 with the following status: 0.

Event[756]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:03:46.166
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[757]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:03:47.720
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[758]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:57.019
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_3f929cc119e3b994\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&8F1C284&0&0009 with the following status: 0x0.

Event[759]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:57.695
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0101 with the following status: 0.

Event[760]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:58.110
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0101 with the following status: 0x0.

Event[761]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:58.378
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0001 with the following status: 0.

Event[762]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:58.710
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0001 with the following status: 0x0.

Event[763]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:58.932
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0201 with the following status: 0.

Event[764]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:59.411
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0201 with the following status: 0x0.

Event[765]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:03:59.743
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0301 with the following status: 0.

Event[766]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-28T13:04:00.106
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&2C0F5796&0&0301 with the following status: 0x0.

Event[767]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:11.654
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\king.com.CandyCrushSodaSaga_kgqvnymyfvs32\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[768]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:12.301
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\9E2F88E3.Twitter_wgeqdkkx372wm\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[769]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:12.824
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[770]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:13.672
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[771]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:14.243
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsPhone_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[772]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:14.733
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[773]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:15.703
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsDVDPlayer_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[774]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:16.240
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[775]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:16.958
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[776]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:17.434
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[777]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:18.026
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.OneConnect_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[778]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:18.512
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Office.Sway_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[779]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:18.893
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[780]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:19.376
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[781]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:20.088
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages.

Event[782]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:20.796
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 43 keys and creating 4 modified pages.

Event[783]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:21.304
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Messaging_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 2 keys and creating 1 modified pages.

Event[784]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:21.737
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.ConnectivityStore_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[785]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:22.118
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.CommsPhone_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 5 keys and creating 1 modified pages.

Event[786]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:22.603
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[787]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:23.035
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[788]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:23.465
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[789]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:23.916
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Appconnector_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[790]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:04:24.257
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.3DBuilder_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.

Event[791]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:05:34.423
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[792]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:05:47.705
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[793]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-28T13:06:46.892
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[794]:
  Log Name: System
  Source: Application Popup
  Date: 2017-01-28T13:17:19.350
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Application popup: Windows - Out of Virtual Memory : Your system is low on virtual memory. To ensure that Windows runs properly, increase the size of your virtual memory paging file. For more information, see Help. 

Event[795]:
  Log Name: System
  Source: Application Popup
  Date: 2017-01-28T13:17:19.820
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Application popup: Java(TM) Web Start 11.111.2.14-fcs : Error encountered while invoking Java Web Start (SysExec) 
C:\Program Files (x86)\Java\jre1.8.0_111\bin\javaws.exe

Event[796]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-28T13:21:46.941
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[797]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-28T13:22:46.963
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[798]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:24:18.792
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[799]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:26:18.792
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[800]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:26:18.933
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[801]:
  Log Name: System
  Source: User32
  Date: 2017-01-28T13:26:22.246
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: restart
 Comment: 

Event[802]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:26:27.482
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[803]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T13:26:26.840
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[804]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T13:26:27.471
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[805]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:26:50.116
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[806]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:26:50.116
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[807]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T13:26:50.116
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[808]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:26:27.606
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[809]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:26:27.613
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[810]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T13:26:32.442
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[811]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:26:32.744
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?28T19:26:32.744327700Z.

Event[812]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:26:43.661
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?28T19:26:43.495059500Z.

Event[813]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.661
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[814]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.661
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[815]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.662
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[816]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.662
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[817]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.662
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[818]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.662
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[819]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-28T13:26:43.662
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[820]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:47.414
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[821]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:47.415
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?07?-?15T20:27:07.000000000Z) has successfully loaded and registered with Filter Manager.

Event[822]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:47.415
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[823]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:26:47.806
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[824]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:47.849
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[825]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:47.899
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[826]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T13:26:47.911
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[827]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-28T13:26:48.073
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[828]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-28T13:26:48.074
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[829]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-28T13:26:48.240
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[830]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:26:48.263
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[831]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:26:48.595
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[832]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:26:48.598
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[833]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:26:48.598
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[834]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-28T13:26:48.599
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[835]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:26:48.651
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[836]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:26:48.757
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[837]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T13:26:48.776
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[838]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:49.218
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[839]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T13:26:49.736
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[840]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T13:26:49.831
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[841]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-28T13:26:49.837
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[842]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[843]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[844]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[845]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[846]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[847]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[848]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-28T13:26:50.038
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[849]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:50.083
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[850]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:50.086
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?07?-?15T20:27:16.000000000Z) has successfully loaded and registered with Filter Manager.

Event[851]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:50.087
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[852]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-28T13:26:50.089
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[853]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-28T13:26:50.219
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[854]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T13:26:50.229
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[855]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.288
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec.

Event[856]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.377
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[857]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.379
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[858]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.386
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[859]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.389
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan definition. Additional Data: Error Value: C:\Program Files\Microsoft Security Client\MpCmdRun.exe.

Event[860]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.392
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[861]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.394
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task definition. Additional Data: Error Value: C:\Users\Roberto\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe.

Event[862]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.404
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[863]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.404
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[864]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.405
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[865]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.406
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[866]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.410
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe.

Event[867]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.411
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[868]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.413
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[869]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.420
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[870]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.421
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[871]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:26:50.413
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[872]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:26:50.429
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[873]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.430
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\OneDrive Standalone Update Task v2 definition. Additional Data: Error Value: %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe.

Event[874]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.437
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[875]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.440
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[876]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.466
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe.

Event[877]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.471
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[878]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.480
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.

Event[879]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.487
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[880]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.490
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[881]:
  Log Name: System
  Source: Microsoft-Windows-TaskScheduler
  Date: 2017-01-28T13:26:50.493
  Event ID: 414
  Task: Task Misconfiguration
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe.

Event[882]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T13:26:50.902
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[883]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-28T13:26:51.412
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[884]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:26:51.897
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[885]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:26:51.898
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[886]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-28T13:26:51.996
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[887]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-28T13:26:52.183
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[888]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-28T13:26:51.954
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[889]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T13:26:52.013
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[890]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:26:52.719
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[891]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:26:52.721
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[892]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:26:52.783
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[893]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-28T13:26:59.750
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[894]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:27:37.927
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[895]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:28:52.904
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[896]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-28T13:29:01.969
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[897]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:30:54.924
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[898]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-28T13:37:13.256
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[899]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:44:42.464
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  MBAMSwissArmy
Service File Name:  C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[900]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T13:45:20.218
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  MBAMSwissArmy
Service File Name:  C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[901]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:20.345
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-18-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[902]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:20.360
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-19-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[903]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:20.372
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-20-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[904]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:20.531
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-3212359789-2164199213-3318592535-1000-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[905]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:20.560
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-3212359789-2164199213-3318592535-1000-0-UsrClass.dat was cleared updating 0 keys and creating 0 modified pages.

Event[906]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:24.334
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-18-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[907]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:24.349
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-19-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[908]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:24.363
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-20-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[909]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:24.520
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-3212359789-2164199213-3318592535-1000-0-ntuser.dat was cleared updating 0 keys and creating 0 modified pages.

Event[910]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T13:45:24.552
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-3212359789-2164199213-3318592535-1000-0-UsrClass.dat was cleared updating 0 keys and creating 0 modified pages.

Event[911]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T14:06:38.355
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[912]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-28T14:36:14.088
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[913]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:30:29.723
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[914]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:30:29.723
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[915]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:30:29.724
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[916]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:30:34.488
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[917]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:30:38.361
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[918]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:30:40.788
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[919]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:31:04.252
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[920]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:33:21.025
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[921]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:33:49.335
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[922]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:33:50.243
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[923]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-28T15:46:19.628
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume ?? (\Device\HarddiskVolumeShadowCopy1) is healthy.  No action is needed.

Event[924]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-28T15:46:20.267
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[925]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:46:24.468
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3213986)

Event[926]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:21.871
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3214628)

Event[927]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:24.502
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Security Update for Adobe Flash Player for Windows 10 Version 1607 (for x64-based Systems) (KB3214628)

Event[928]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:24.674
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Update for Windows 10 Version 1607 for x64-based Systems (KB3211320)

Event[929]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:26.990
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Update for Windows 10 Version 1607 for x64-based Systems (KB3211320)

Event[930]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:27.014
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1519.0)

Event[931]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-28T15:51:56.386
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1519.0)

Event[932]:
  Log Name: System
  Source: User32
  Date: 2017-01-28T15:59:47.235
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[933]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-28T15:59:51.470
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[934]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-28T16:01:33.997
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[935]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-28T16:01:33.996
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[936]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T16:01:34.109
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[937]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T10:41:40.187
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[938]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T10:41:40.187
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[939]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T10:41:40.187
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[940]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-28T16:01:34.117
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[941]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T16:01:38.971
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[942]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-28T16:01:38.971
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[943]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-28T16:01:39.563
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?28T22:01:39.563816900Z.

Event[944]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T10:41:32.663
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?29T16:41:32.495057700Z.

Event[945]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[946]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[947]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[948]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[949]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[950]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[951]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T10:41:32.663
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[952]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:36.400
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[953]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:36.400
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[954]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:36.400
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[955]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T10:41:36.727
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[956]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:36.777
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[957]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:36.825
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[958]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T10:41:36.841
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[959]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-29T10:41:36.928
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[960]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-29T10:41:36.928
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[961]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-29T10:41:37.068
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[962]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T10:41:37.152
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[963]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T10:41:37.423
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[964]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T10:41:37.426
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[965]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T10:41:37.426
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[966]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T10:41:37.426
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[967]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T10:41:37.531
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[968]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T10:41:37.639
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[969]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T10:41:37.659
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[970]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:38.758
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[971]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T10:41:39.863
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[972]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T10:41:39.961
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[973]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T10:41:39.967
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[974]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[975]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[976]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[977]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[978]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[979]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[980]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T10:41:40.187
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[981]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:40.195
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[982]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:40.223
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[983]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:40.225
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[984]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T10:41:40.227
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[985]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-29T10:41:40.232
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[986]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-29T10:41:40.240
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[987]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:41:40.531
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[988]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:41:40.531
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[989]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T10:41:40.614
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[990]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T10:41:40.654
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[991]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:41:40.796
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[992]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-29T10:41:40.821
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[993]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-29T10:41:41.011
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[994]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-29T10:41:41.810
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[995]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-29T10:41:41.827
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[996]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-29T10:41:40.934
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[997]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:41:41.816
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[998]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:41:41.821
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[999]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:41:41.822
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[1000]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:41:41.826
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Media Player Network Sharing Service service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[1001]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T10:41:44.052
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0.

Event[1002]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T10:41:44.663
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_4230b9b7f6bb1278\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0x0.

Event[1003]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T10:41:49.901
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1004]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T10:41:52.003
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[1005]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-01-29T10:41:52.964
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[1006]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:43:41.944
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1007]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:44:41.307
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout.

Event[1008]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T10:44:57.269
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_3f929cc119e3b994\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[1009]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:00.122
  Event ID: 15008
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10246/MDEServer/ was successfully deleted.

Event[1010]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:00.138
  Event ID: 15008
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix https://+:10245/WMPNSSv4/ was successfully deleted.

Event[1011]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:00.138
  Event ID: 15008
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10243/WMPNSSv4/ was successfully deleted.

Event[1012]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:00.216
  Event ID: 15008
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10247/apps/ was successfully deleted.

Event[1013]:
  Log Name: System
  Source: Microsoft-Windows-Eventlog
  Date: 2017-01-29T10:45:05.929
  Event ID: 30
  Task: Service startup
  Level: Error
  Opcode: Info
  Keyword: Service availability
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The event logging service encountered an error (5) while enabling publisher {0BF2FB94-7B60-4B4D-9766-E82F658DF540} to channel Microsoft-Windows-Kernel-ShimEngine/Operational. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Event[1014]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:21.421
  Event ID: 15007
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10247/apps/ was successfully added.

Event[1015]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:21.484
  Event ID: 15007
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix https://+:10245/WMPNSSv4/ was successfully added.

Event[1016]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:21.484
  Event ID: 15007
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10243/WMPNSSv4/ was successfully added.

Event[1017]:
  Log Name: System
  Source: Microsoft-Windows-HttpEvent
  Date: 2017-01-29T10:45:21.531
  Event ID: 15007
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Reservation for namespace identified by URL prefix http://+:10246/MDEServer/ was successfully added.

Event[1018]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:45:22.921
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[1019]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-29T10:45:23.106
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1020]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:45:23.281
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1021]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:45:23.359
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1022]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:45:23.374
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1023]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T10:45:26.758
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Windows.ShellExperienceHost_10.0.14393.693_neutral_neutral_cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[1024]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T10:45:27.166
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.AccountsControl_10.0.14393.693_neutral__cw5n1h2txyewy\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[1025]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T10:45:29.704
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB3213986)

Event[1026]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:45:29.929
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1027]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:45:44.484
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1028]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T10:46:25.209
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1029]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T10:46:30.244
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1575.0)

Event[1030]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T10:46:35.665
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1575.0)

Event[1031]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:46:55.226
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1032]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:47:29.931
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1033]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:47:29.960
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1034]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T10:48:57.257
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1035]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T10:49:29.957
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1036]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-29T10:51:28.169
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[1037]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-29T10:52:28.190
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[1038]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-29T11:00:23.788
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1039]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T11:00:35.282
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1040]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T11:02:35.286
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1041]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T11:02:35.318
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1042]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T11:04:35.313
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1043]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T11:45:05.931
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1044]:
  Log Name: System
  Source: User32
  Date: 2017-01-29T11:53:47.481
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1045]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T11:53:50.120
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1046]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-29T11:53:49.608
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1047]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-29T11:53:50.115
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1048]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-29T11:53:50.124
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1049]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T11:53:50.234
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1050]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T16:25:55.455
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1051]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T16:25:55.455
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1052]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T16:25:55.455
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1053]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T11:53:50.238
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1054]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T11:53:55.094
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1055]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T11:53:55.094
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1056]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T11:53:55.455
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?29T17:53:55.455728800Z.

Event[1057]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T16:25:47.659
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?29T22:25:47.495083200Z.

Event[1058]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1059]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1060]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1061]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1062]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1063]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1064]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T16:25:47.660
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1065]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:51.352
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1066]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:51.352
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1067]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:51.352
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1068]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T16:25:51.670
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1069]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:51.715
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1070]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:51.763
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1071]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T16:25:51.776
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1072]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-29T16:25:51.942
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1073]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-29T16:25:51.942
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1074]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T16:25:52.114
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1075]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-29T16:25:52.115
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1076]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T16:25:52.470
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1077]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T16:25:52.473
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1078]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T16:25:52.473
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1079]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T16:25:52.473
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1080]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T16:25:52.492
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1081]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T16:25:52.601
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1082]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T16:25:52.621
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1083]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:53.787
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1084]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T16:25:54.220
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1085]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T16:25:54.312
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1086]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T16:25:54.318
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1087]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-29T16:25:56.033
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1088]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1089]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1090]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1091]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1092]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1093]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1094]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T16:25:55.455
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1095]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:55.462
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1096]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:55.493
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1097]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:55.495
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1098]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T16:25:55.498
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1099]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-29T16:25:55.503
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1100]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-29T16:25:55.513
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1101]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:25:55.876
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1102]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-29T16:25:55.876
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1103]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-29T16:25:56.034
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1104]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T16:25:56.064
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1105]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T16:25:56.222
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1106]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-29T16:25:57.027
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1107]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-29T16:25:56.691
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1108]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:25:57.032
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1109]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T16:25:57.305
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1110]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T16:25:57.315
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1111]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T16:25:57.575
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver e2414h.inf_amd64_963a890bd17b6fb1\e2414h.inf for Device Instance ID DISPLAY\DEL4090\5&3304A03A&0&UID4355 with the following status: 0x0.

Event[1112]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T16:25:57.643
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver e2414h.inf_amd64_963a890bd17b6fb1\e2414h.inf for Device Instance ID DISPLAY\DEL4090\5&3304A03A&0&UID4354 with the following status: 0x0.

Event[1113]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T16:26:04.256
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1114]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T16:27:40.281
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1115]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:27:57.172
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1116]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:29:59.158
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1117]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:30:56.706
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1118]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T16:31:10.770
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1119]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T16:31:10.770
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1578.0)

Event[1120]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T16:31:42.726
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1578.0)

Event[1121]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T16:32:59.547
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1122]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-01-29T16:33:59.787
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name www.orderflowanalytics.com timed out after none of the configured DNS servers responded.

Event[1123]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-29T16:40:58.061
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1124]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:15:50.232
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1125]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T17:34:43.666
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?29T23:34:43.495158400Z.

Event[1126]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.666
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1127]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.666
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was false. The last boot's success status was true.

Event[1128]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.667
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1129]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.667
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1130]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.667
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1131]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.667
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1132]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-29T17:34:43.667
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1133]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T17:34:51.750
  Event ID: 6008
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The previous system shutdown at 5:33:55 PM on ?1/?29/?2017 was unexpected.

Event[1134]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T17:34:51.750
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1135]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T17:34:51.750
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1136]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T17:34:51.750
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 8 seconds.

Event[1137]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:47.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1138]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:47.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1139]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:47.400
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1140]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T17:34:47.735
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1141]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:47.781
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1142]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:47.829
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1143]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T17:34:47.841
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Event[1144]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T17:34:47.842
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1145]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-29T17:34:48.007
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1146]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-29T17:34:48.008
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1147]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-29T17:34:48.178
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1148]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T17:34:48.225
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1149]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T17:34:48.533
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1150]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T17:34:48.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1151]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T17:34:48.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1152]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-29T17:34:48.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1153]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T17:34:48.646
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1154]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T17:34:48.751
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1155]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-29T17:34:48.772
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1156]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:49.427
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1157]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T17:34:50.566
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1158]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T17:34:50.659
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1159]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-29T17:34:50.663
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1160]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-29T17:34:52.448
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1161]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:51.736
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1162]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:51.738
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1163]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:51.741
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1164]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-29T17:34:51.744
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1165]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1166]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1167]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1168]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1169]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1170]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1171]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-29T17:34:51.750
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1172]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-29T17:34:51.777
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1173]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-29T17:34:51.787
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1174]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-29T17:34:51.954
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1175]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:34:52.172
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1176]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:34:52.172
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1177]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T17:34:52.181
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1178]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T17:34:52.264
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1179]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-29T17:34:52.377
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1180]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:34:52.391
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1181]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-29T17:34:53.736
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1182]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-29T17:34:53.759
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[1183]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-29T17:34:53.463
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1184]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:34:53.740
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1185]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:34:53.751
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1186]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:34:53.752
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[1187]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:34:53.759
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Media Player Network Sharing Service service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[1188]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:34:54.150
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1189]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:34:54.155
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1190]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-29T17:35:00.586
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1191]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-01-29T17:35:02.020
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[1192]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:35:31.532
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1193]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:36:53.870
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1194]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-29T17:37:03.455
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1195]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:38:55.903
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1196]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-29T17:49:54.474
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1197]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:52:23.295
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[1198]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:52:25.634
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_02838dee03d82b94\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[1199]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:52:45.279
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0.

Event[1200]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:52:45.595
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0x0.

Event[1201]:
  Log Name: System
  Source: Display
  Date: 2017-01-29T17:53:16.672
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1202]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:53:19.083
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvvad_WaveExtensible for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0.

Event[1203]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T17:53:19.163
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvvad.inf_amd64_f027e470fd029b8e\nvvad.inf for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0x0.

Event[1204]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T17:53:20.523
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA KMS
Service File Name:  C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1205]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:27.864
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA Wireless Controller Service service was changed from auto start to disabled.

Event[1206]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:31.124
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA NetworkService Container service was changed from demand start to disabled.

Event[1207]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:31.371
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA LocalSystem Container service was changed from auto start to disabled.

Event[1208]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:32.502
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA Display Container LS service was changed from auto start to disabled.

Event[1209]:
  Log Name: System
  Source: Display
  Date: 2017-01-29T18:00:38.630
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1210]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:40.131
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the Service for NVIDIA High Definition Audio Driver service was changed from demand start to disabled.

Event[1211]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:41.290
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA Virtual Audio Device (Wave Extensible) (WDM) service was changed from demand start to disabled.

Event[1212]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:00:53.776
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The start type of the nvlddmkm service was changed from demand start to disabled.

Event[1213]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:01:41.128
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the nvlddmkm service was changed from disabled to demand start.

Event[1214]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:01:41.133
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[1215]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:01:42.200
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_02838dee03d82b94\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[1216]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:01:45.871
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Display Container LS
Service File Name:  "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[1217]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:01:58.472
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Service for NVIDIA High Definition Audio Driver service was changed from disabled to demand start.

Event[1218]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:01:58.480
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0.

Event[1219]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:01:58.787
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0x0.

Event[1220]:
  Log Name: System
  Source: Display
  Date: 2017-01-29T18:02:29.767
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1221]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:02:32.336
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA Virtual Audio Device (Wave Extensible) (WDM) service was changed from disabled to demand start.

Event[1222]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:02:32.344
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvvad_WaveExtensible for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0.

Event[1223]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-29T18:02:32.424
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvvad.inf_amd64_f027e470fd029b8e\nvvad.inf for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0x0.

Event[1224]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:02:33.121
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA LocalSystem Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[1225]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:02:33.221
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA NetworkService Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  NT AUTHORITY\NetworkService

Event[1226]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:02:33.669
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA KMS
Service File Name:  C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1227]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:02:36.527
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Wireless Controller Service
Service File Name:  "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[1228]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T18:38:24.780
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA LocalSystem Container service was changed from demand start to auto start.

Event[1229]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-29T19:05:02.584
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[1230]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-29T19:30:02.579
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[1231]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T19:35:07.621
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1232]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T19:35:07.621
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1592.0)

Event[1233]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-29T19:35:41.496
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1592.0)

Event[1234]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-29T19:58:17.199
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1235]:
  Log Name: System
  Source: User32
  Date: 2017-01-29T19:58:20.254
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1236]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-29T19:58:24.163
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1237]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-29T19:58:23.544
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1238]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-29T19:58:24.180
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1239]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-29T19:58:24.181
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1240]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T10:02:11.458
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1241]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T10:02:11.458
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1242]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T10:02:11.458
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1243]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T19:58:24.282
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1244]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-29T19:58:24.285
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1245]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T19:58:29.136
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1246]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-29T19:58:29.136
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1247]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-29T19:58:29.515
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T01:58:29.515024300Z.

Event[1248]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T10:02:04.492
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T16:02:04.341806300Z.

Event[1249]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.492
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1250]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.492
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1251]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.493
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1252]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.493
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1253]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.493
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1254]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.493
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1255]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T10:02:04.493
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1256]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:08.205
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1257]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:08.205
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1258]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:08.205
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1259]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T10:02:08.572
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1260]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:08.619
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1261]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:08.667
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1262]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T10:02:08.680
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1263]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T10:02:08.848
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1264]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T10:02:08.848
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1265]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T10:02:09.015
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1266]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T10:02:09.019
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1267]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T10:02:09.369
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1268]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T10:02:09.372
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1269]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T10:02:09.372
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1270]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T10:02:09.373
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1271]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T10:02:09.407
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1272]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T10:02:09.514
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1273]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T10:02:09.534
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1274]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:10.665
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1275]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T10:02:11.088
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1276]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T10:02:11.186
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1277]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T10:02:11.192
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1278]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1279]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1280]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1281]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1282]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1283]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1284]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T10:02:11.380
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1285]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:11.426
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1286]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:11.428
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1287]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:11.431
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1288]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T10:02:11.432
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1289]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T10:02:11.650
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1290]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T10:02:11.661
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1291]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T10:02:11.948
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1292]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T10:02:11.948
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1293]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T10:02:12.240
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1294]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T10:02:12.621
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1295]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T10:02:12.716
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1296]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T10:02:12.727
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1297]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T10:02:12.801
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1298]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T10:02:13.221
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1299]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T10:02:12.739
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1300]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T10:02:12.866
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1301]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T10:02:13.728
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1302]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T10:02:13.747
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1303]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T10:02:13.750
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1304]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T10:02:21.113
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1305]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T10:04:13.732
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1306]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T10:04:22.083
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1307]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T10:04:25.689
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1308]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T10:04:28.383
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1309]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T10:04:27.932
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1310]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T10:04:28.390
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1311]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T10:04:28.393
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1312]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T11:44:24.476
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1313]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T11:44:24.476
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1314]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T11:44:24.476
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1315]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T10:04:28.499
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1316]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T10:04:28.556
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1317]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T10:04:33.364
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1318]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T10:04:33.364
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1319]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T10:04:33.614
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T16:04:33.614425100Z.

Event[1320]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T11:44:16.645
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T17:44:16.495106300Z.

Event[1321]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1322]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1323]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1324]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1325]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1326]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1327]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T11:44:16.645
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1328]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:20.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1329]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:20.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1330]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:20.399
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1331]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T11:44:20.731
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1332]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:20.777
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1333]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:20.825
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1334]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T11:44:20.838
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1335]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T11:44:21.005
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1336]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T11:44:21.005
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1337]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T11:44:21.177
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1338]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T11:44:21.177
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1339]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T11:44:21.533
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1340]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T11:44:21.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1341]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T11:44:21.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1342]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T11:44:21.536
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1343]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T11:44:21.556
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1344]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T11:44:21.664
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1345]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T11:44:21.684
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1346]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:22.215
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1347]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T11:44:23.300
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1348]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T11:44:23.392
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1349]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T11:44:23.397
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1350]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T11:44:25.190
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1351]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1352]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1353]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1354]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1355]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1356]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1357]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T11:44:24.476
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1358]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:24.515
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1359]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:24.518
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1360]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:24.521
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1361]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T11:44:24.523
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1362]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T11:44:24.527
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1363]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T11:44:24.538
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1364]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T11:44:24.898
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1365]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:44:24.929
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1366]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:44:24.929
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1367]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T11:44:24.947
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1368]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:44:24.992
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1369]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T11:44:25.019
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1370]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T11:44:25.134
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1371]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T11:44:26.107
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1372]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T11:44:26.292
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[1373]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T11:44:25.966
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1374]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:44:26.245
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1375]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:44:26.252
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[1376]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:44:26.283
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[1377]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:44:26.444
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1378]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:44:26.589
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1379]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:44:26.592
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1380]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T11:44:33.321
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1381]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:45:15.576
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1382]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:46:26.449
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1383]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:46:33.209
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1384]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T11:46:44.302
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1385]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:48:51.091
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1386]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:48:53.386
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1387]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:49:31.159
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1388]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:49:35.309
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1389]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:52:25.467
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1390]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:54:28.249
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1391]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:54:33.870
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1392]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T11:54:36.189
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1393]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T11:55:23.103
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1394]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T11:55:32.472
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\WINDOWS\Explorer.EXE (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1395]:
  Log Name: System
  Source: Application Popup
  Date: 2017-01-30T11:55:35.151
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Application popup: explorer.exe - Application Error : The instruction at 0x000000006460B00C referenced memory at 0x000000006460B00C. The memory could not be written.

Click on OK to terminate the program

Event[1396]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T11:55:44.202
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1397]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T11:55:43.656
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1398]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T11:55:44.199
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1399]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T11:55:44.204
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1400]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:19:17.167
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1401]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:19:17.167
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1402]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:19:17.167
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1403]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T11:55:44.315
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1404]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T11:55:44.318
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1405]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T11:55:49.174
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1406]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T11:55:49.174
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1407]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T11:55:49.577
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T17:55:49.577370200Z.

Event[1408]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:19:09.646
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T18:19:09.495186200Z.

Event[1409]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1410]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1411]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1412]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1413]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1414]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1415]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:19:09.646
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1416]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:13.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1417]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:13.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1418]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:13.369
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1419]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:19:13.701
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1420]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:13.748
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1421]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:13.797
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1422]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:19:13.810
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1423]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T12:19:13.978
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1424]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T12:19:13.978
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1425]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:19:14.145
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1426]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T12:19:14.147
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1427]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:19:14.502
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1428]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:19:14.505
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1429]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:19:14.505
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1430]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:19:14.506
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1431]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:19:14.524
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1432]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:19:14.633
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1433]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:19:14.653
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1434]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:15.183
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1435]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:19:16.218
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1436]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:19:16.317
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1437]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:19:16.323
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1438]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T12:19:17.927
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1439]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1440]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1441]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1442]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1443]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1444]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1445]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:19:17.120
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1446]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:17.153
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1447]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:17.156
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1448]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:17.158
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1449]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:19:17.160
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1450]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:19:17.188
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1451]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:19:17.196
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1452]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:19:17.526
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1453]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:19:17.526
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1454]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:19:17.713
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1455]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:19:17.755
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1456]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:19:17.828
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1457]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T12:19:17.854
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1458]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T12:19:17.886
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1459]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T12:19:18.949
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1460]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:19:18.442
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1461]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:19:18.956
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1462]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:19:19.401
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1463]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:19:19.417
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1464]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:19:26.264
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1465]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:20:38.687
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1466]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:21:19.077
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1467]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:21:28.643
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1468]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T12:24:58.099
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1469]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T12:25:02.186
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1470]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:29:36.722
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  PAExec
Service File Name:  C:\WINDOWS\PAExec.exe -service
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[1471]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:29:36.722
  Event ID: 7030
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The PAExec service is marked as an interactive service.  However, the system is configured to not allow interactive services.  This service may not function properly.

Event[1472]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:30:50.124
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume ?? (\Device\HarddiskVolumeShadowCopy2) is healthy.  No action is needed.

Event[1473]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:31:51.314
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BasicDisplay for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[1474]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:31:51.356
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver display.inf_amd64_d52ffbbc7f640691\display.inf for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[1475]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T12:31:51.474
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\shutdown.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user NT AUTHORITY\SYSTEM for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: restart
 Comment: 

Event[1476]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:31:51.671
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Microsoft 1.1 UAA Function Driver for High Definition Audio Service
Service File Name:  \SystemRoot\system32\DRIVERS\HdAudio.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1477]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:31:51.672
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service HdAudAddService for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0.

Event[1478]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:31:51.807
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver hdaudio.inf_amd64_04c3e2018e8e6dfd\hdaudio.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0x0.

Event[1479]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.173
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1480]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.184
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1481]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.196
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1482]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.244
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1483]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.252
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1484]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:31:52.675
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} did not register with DCOM within the required timeout.

Event[1485]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:31:53.848
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1486]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:31:53.381
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1487]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:31:53.853
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1488]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:31:53.853
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1489]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:32:18.712
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1490]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:32:18.712
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1491]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:32:18.712
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[1492]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:31:53.965
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1493]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:31:54.022
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1494]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:31:58.820
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1495]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:31:59.465
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T18:31:59.465786800Z.

Event[1496]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:32:12.642
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T18:32:12.495071800Z.

Event[1497]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1498]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1499]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1500]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1501]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1502]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1503]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:32:12.642
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1504]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:16.367
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1505]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:16.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1506]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:16.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1507]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:32:16.669
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1508]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:16.716
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1509]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:16.764
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1510]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:32:16.777
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1511]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T12:32:16.865
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1512]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T12:32:16.865
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1513]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T12:32:17.037
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1514]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:32:17.089
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1515]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:32:17.392
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1516]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:32:17.395
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1517]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:32:17.395
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1518]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:32:17.396
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1519]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:32:17.485
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1520]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:32:17.591
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1521]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:32:17.611
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1522]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.077
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1523]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:32:18.385
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1524]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:32:18.484
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1525]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:32:18.489
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1526]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1527]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1528]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1529]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1530]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1531]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1532]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:32:18.697
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1533]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:18.721
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1534]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:18.749
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1535]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:18.751
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1536]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:32:18.754
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1537]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:32:18.758
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1538]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:32:18.767
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1539]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:32:19.039
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1540]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:32:19.039
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1541]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T12:32:20.848
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1542]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T12:32:21.175
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1543]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T12:32:20.202
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1544]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:32:20.562
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1545]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:32:20.702
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1546]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:32:20.747
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1547]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T12:32:20.765
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1548]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:32:20.862
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1549]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:32:21.599
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1550]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:32:21.760
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1551]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:32:21.763
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1552]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:32:28.408
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1553]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:34:06.494
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1554]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:34:21.733
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1555]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:34:31.352
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1556]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:36:23.830
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1557]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:36:35.421
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  nvlddmkm
Service File Name:  \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_02838dee03d82b94\nvlddmkm.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1558]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:36:35.428
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[1559]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:36:36.327
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_02838dee03d82b94\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_1402&SUBSYS_85541043&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[1560]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:36:40.797
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Display Container LS
Service File Name:  "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[1561]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:36:54.163
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Service for NVIDIA High Definition Audio Driver
Service File Name:  \SystemRoot\system32\drivers\nvhda64v.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1562]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:36:54.168
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0.

Event[1563]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:36:54.493
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0072&SUBSYS_10438554&REV_1001\5&3793331C&0&0001 with the following status: 0x0.

Event[1564]:
  Log Name: System
  Source: Display
  Date: 2017-01-30T12:37:25.751
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[1565]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:28.233
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
Service File Name:  \SystemRoot\system32\drivers\nvvad64v.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1566]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:37:28.241
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvvad_WaveExtensible for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0.

Event[1567]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-01-30T12:37:28.325
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvvad.inf_amd64_f027e470fd029b8e\nvvad.inf for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0x0.

Event[1568]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:30.599
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA LocalSystem Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  LocalSystem

Event[1569]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:30.700
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA NetworkService Container
Service File Name:  "C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\NetworkService" -r -p 30000
Service Type:  user mode service
Service Start Type:  demand start
Service Account:  NT AUTHORITY\NetworkService

Event[1570]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:31.116
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA KMS
Service File Name:  C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1571]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:34.741
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  NVIDIA Wireless Controller Service
Service File Name:  "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
Service Type:  user mode service
Service Start Type:  auto start
Service Account:  LocalSystem

Event[1572]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:47.832
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the NVIDIA LocalSystem Container service was changed from demand start to auto start.

Event[1573]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:37:50.194
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1574]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T12:37:53.347
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: restart
 Comment: 

Event[1575]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:37:57.141
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1576]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:37:56.582
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1577]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:37:57.135
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1578]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:37:57.143
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1579]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:37:57.240
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1580]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:38:22.483
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1581]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:38:22.483
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1582]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:38:22.483
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1583]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:37:57.243
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1584]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:38:02.113
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1585]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:38:02.431
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T18:38:02.431770300Z.

Event[1586]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:38:14.645
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T18:38:14.495076700Z.

Event[1587]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1588]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1589]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1590]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1591]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1592]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1593]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:38:14.645
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1594]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:18.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1595]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:18.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1596]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:18.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1597]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:38:18.693
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1598]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:18.738
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1599]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:18.787
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1600]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:38:18.800
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1601]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T12:38:18.968
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1602]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T12:38:18.968
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1603]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:38:19.136
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1604]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T12:38:19.146
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1605]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:38:19.503
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1606]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:38:19.506
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1607]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:38:19.506
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1608]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:38:19.506
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1609]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:38:19.540
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1610]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:38:19.647
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1611]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:38:19.667
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1612]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:20.188
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1613]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:38:21.286
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1614]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:38:21.379
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1615]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:38:21.386
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1616]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T12:38:23.124
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1617]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T12:38:22.296
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1618]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1619]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1620]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1621]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1622]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1623]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1624]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:38:22.437
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1625]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:22.472
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1626]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:22.475
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1627]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:22.477
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1628]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:38:22.479
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1629]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:38:22.506
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1630]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:38:22.515
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1631]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:38:22.905
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1632]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:38:22.937
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1633]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:38:22.999
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1634]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:38:23.050
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1635]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T12:38:23.054
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1636]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:38:23.226
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1637]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:38:23.761
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1638]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:38:24.294
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1639]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:38:24.294
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1640]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T12:38:24.389
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1641]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:38:24.393
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1642]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:38:31.318
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1643]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:40:01.980
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1644]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:40:24.529
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1645]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:40:34.882
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1646]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:42:26.565
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1647]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:51:36.993
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1648]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T12:51:41.177
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: restart
 Comment: 

Event[1649]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:51:44.417
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1650]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:51:43.622
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1651]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:51:44.346
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1652]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:51:44.351
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1653]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:52:09.499
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1654]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:52:09.499
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1655]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T12:52:09.499
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1656]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:51:44.467
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1657]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:51:44.575
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1658]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:51:49.317
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1659]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:51:49.648
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T18:51:49.648149200Z.

Event[1660]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T12:52:02.645
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?30T18:52:02.495152500Z.

Event[1661]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.645
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1662]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.645
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1663]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.646
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1664]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.646
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1665]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.646
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1666]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.646
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1667]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-30T12:52:02.646
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1668]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:06.367
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1669]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:06.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1670]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:06.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1671]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:52:06.693
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1672]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:06.739
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1673]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:06.787
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1674]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T12:52:06.800
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1675]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-30T12:52:06.969
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1676]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-30T12:52:06.970
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1677]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:52:07.135
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1678]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-30T12:52:07.146
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1679]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:52:07.502
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1680]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:52:07.504
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1681]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:52:07.505
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1682]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-30T12:52:07.505
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1683]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:52:07.539
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1684]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:52:07.646
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1685]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-30T12:52:07.666
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1686]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:08.187
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1687]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:52:09.101
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1688]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:52:09.201
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1689]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-30T12:52:09.208
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1690]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1691]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1692]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1693]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1694]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1695]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1696]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-30T12:52:09.419
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1697]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:09.455
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1698]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:09.458
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1699]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:09.460
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1700]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-30T12:52:09.462
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1701]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T12:52:09.516
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1702]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T12:52:09.528
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1703]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:52:09.952
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1704]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:52:09.952
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1705]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-30T12:52:11.007
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1706]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-30T12:52:10.296
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1707]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T12:52:10.654
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1708]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:52:10.836
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1709]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:52:10.910
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1710]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-30T12:52:10.933
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1711]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T12:52:11.022
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1712]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-30T12:52:11.475
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1713]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:52:11.749
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1714]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:52:11.766
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1715]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:52:11.769
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1716]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-30T12:52:19.145
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1717]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:54:11.870
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1718]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:54:21.166
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1719]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T12:56:13.862
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1720]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-30T12:57:01.340
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1721]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-30T13:07:12.460
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1722]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T13:57:43.225
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  EnTech softEngine
Service File Name:  system32\drivers\se64a.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[1723]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-30T13:59:25.460
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1724]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-30T14:06:05.200
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[1725]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-30T14:07:05.221
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[1726]:
  Log Name: System
  Source: User32
  Date: 2017-01-30T14:17:05.919
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1727]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-30T14:17:08.956
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1728]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-30T14:17:08.392
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1729]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-30T14:17:08.959
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1730]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-30T14:17:08.965
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1731]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T09:30:12.526
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1732]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T09:30:12.526
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1733]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T09:30:12.541
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1734]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T14:17:09.072
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1735]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-30T14:17:09.077
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1736]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T14:17:13.930
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1737]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-30T14:17:13.930
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1738]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-30T14:17:14.167
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?30T20:17:14.167325800Z.

Event[1739]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T09:30:05.646
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?31T15:30:05.495164300Z.

Event[1740]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.646
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1741]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.646
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1742]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.647
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1743]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.647
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1744]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.647
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1745]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.647
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1746]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T09:30:05.647
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1747]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:09.367
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1748]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:09.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1749]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:09.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1750]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T09:30:09.696
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1751]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:09.743
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1752]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:09.791
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1753]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T09:30:09.805
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1754]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-31T09:30:09.972
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1755]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-31T09:30:09.973
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1756]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T09:30:10.137
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1757]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-31T09:30:10.146
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1758]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T09:30:10.501
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1759]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T09:30:10.504
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1760]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T09:30:10.504
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1761]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T09:30:10.505
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1762]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T09:30:10.525
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1763]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T09:30:10.633
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1764]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T09:30:10.653
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1765]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:11.182
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1766]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-31T09:30:12.102
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1767]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-31T09:30:12.199
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1768]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-31T09:30:12.204
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1769]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1770]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1771]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1772]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1773]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1774]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1775]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T09:30:12.541
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1776]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:12.543
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1777]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:12.571
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1778]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:12.573
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1779]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T09:30:12.576
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1780]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-31T09:30:12.580
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1781]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-31T09:30:12.591
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1782]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:30:12.948
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1783]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:30:12.948
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1784]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-31T09:30:14.000
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1785]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-31T09:30:14.445
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1786]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-31T09:30:13.643
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1787]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:30:13.839
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1788]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-31T09:30:13.885
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1789]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-31T09:30:13.962
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1790]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T09:30:14.024
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1791]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T09:30:14.103
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1792]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:30:14.567
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1793]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-31T09:30:14.605
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[1794]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:30:14.582
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[1795]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:30:14.600
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[1796]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:30:14.728
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1797]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:30:14.954
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1798]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:30:14.957
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1799]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-31T09:30:22.118
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1800]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:32:14.851
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1801]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:32:27.057
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1802]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T09:33:56.763
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1803]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:34:16.844
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1804]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:36:13.871
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1805]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T09:36:50.624
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1806]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T09:36:55.468
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1735.0)

Event[1807]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T09:37:00.471
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1735.0)

Event[1808]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:38:16.508
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1809]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:42:15.447
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1810]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T09:44:36.389
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1811]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-31T09:45:15.694
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1812]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T11:27:52.455
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[1813]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T11:28:52.460
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[1814]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T11:29:52.464
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 3 time(s) since it was last initialized.

Event[1815]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T11:30:52.472
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 4 time(s) since it was last initialized.

Event[1816]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T11:31:52.477
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 5 time(s) since it was last initialized.

Event[1817]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T12:00:00.542
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 8995 seconds.

Event[1818]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T12:00:00.810
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1819]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T12:02:13.610
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1820]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T13:21:26.409
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1821]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T13:39:03.188
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\SYSTEM (TM: {2402D000-E7CA-11E6-AA22-240A6438E79A}, RM: {2402CFFF-E7CA-11E6-AA22-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[1822]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T13:39:03.238
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\DRIVERS (TM: {2402D002-E7CA-11E6-AA22-240A6438E79A}, RM: {2402D001-E7CA-11E6-AA22-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[1823]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T13:39:09.351
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\WINDOWS\System32\config\SYSTEM (TM: {2402D023-E7CA-11E6-AA22-240A6438E79A}, RM: {2402D022-E7CA-11E6-AA22-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[1824]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T13:39:09.428
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\WINDOWS\System32\config\DRIVERS (TM: {2402D025-E7CA-11E6-AA22-240A6438E79A}, RM: {2402D024-E7CA-11E6-AA22-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[1825]:
  Log Name: System
  Source: User32
  Date: 2017-01-31T14:28:34.826
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1826]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T14:28:39.094
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1827]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-31T14:28:38.504
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1828]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-31T14:28:39.087
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1829]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-31T14:28:39.093
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1830]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T17:28:53.589
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1831]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T17:28:53.589
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1832]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T17:28:53.604
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1833]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T14:28:39.196
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1834]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T14:28:39.253
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1835]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T14:28:44.063
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1836]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T14:28:44.063
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1837]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T14:28:44.305
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?01?-?31T20:28:44.305185300Z.

Event[1838]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T17:28:46.646
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?01?-?31T23:28:46.495151400Z.

Event[1839]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1840]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1841]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1842]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1843]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1844]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1845]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-01-31T17:28:46.646
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1846]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:50.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1847]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:50.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1848]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:50.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1849]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T17:28:50.710
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1850]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:50.758
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1851]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:50.806
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1852]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T17:28:50.819
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1853]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-01-31T17:28:50.987
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1854]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-01-31T17:28:50.987
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1855]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T17:28:51.154
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1856]:
  Log Name: System
  Source: MEIx64
  Date: 2017-01-31T17:28:51.162
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1857]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T17:28:51.518
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1858]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T17:28:51.520
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1859]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T17:28:51.521
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1860]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-01-31T17:28:51.521
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1861]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T17:28:51.533
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1862]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T17:28:51.642
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1863]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-01-31T17:28:51.662
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1864]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:52.202
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1865]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-31T17:28:53.118
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1866]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-31T17:28:53.209
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1867]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-01-31T17:28:53.214
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1868]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1869]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1870]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1871]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1872]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1873]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1874]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-01-31T17:28:53.542
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1875]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:53.558
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1876]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:53.582
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1877]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:53.585
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1878]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-01-31T17:28:53.587
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1879]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-31T17:28:53.615
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1880]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-31T17:28:53.626
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1881]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:28:53.964
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1882]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:28:53.964
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1883]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-01-31T17:28:54.984
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1884]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-31T17:28:55.221
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1885]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-01-31T17:28:55.254
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[1886]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-31T17:28:54.623
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1887]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:28:54.791
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1888]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-01-31T17:28:54.900
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1889]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T17:28:54.913
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1890]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-01-31T17:28:54.949
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1891]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T17:28:54.999
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1892]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:28:55.230
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1893]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:28:55.232
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[1894]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:28:55.254
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[1895]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:28:55.681
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1896]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:28:55.886
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1897]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:28:55.890
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1898]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-01-31T17:29:03.142
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1899]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:30:55.671
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1900]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:31:03.914
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1901]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:31:07.693
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1902]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:31:47.456
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1903]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T17:42:27.000
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1904]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T17:42:27.185
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\4DF9E0F8.Netflix_6.17.61.0_x64__mcm4njqhnhss8\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[1905]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T17:42:32.368
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Netflix

Event[1906]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-01-31T17:42:32.368
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Netflix

Event[1907]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T17:42:36.148
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1908]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T17:42:36.150
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\4DF9E0F8.Netflix_mcm4njqhnhss8\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages.

Event[1909]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-01-31T17:43:56.824
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1910]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-01-31T17:44:36.149
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1911]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T18:20:26.821
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[1912]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T18:30:26.820
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[1913]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-01-31T18:51:26.817
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 3 time(s) since it was last initialized.

Event[1914]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-01-31T19:21:57.287
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1915]:
  Log Name: System
  Source: User32
  Date: 2017-01-31T19:22:00.603
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[1916]:
  Log Name: System
  Source: EventLog
  Date: 2017-01-31T19:22:03.677
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[1917]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-01-31T19:22:03.134
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[1918]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-01-31T19:22:03.679
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[1919]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-01-31T19:22:03.686
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[1920]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-01T09:39:26.447
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[1921]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-01T09:39:26.447
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[1922]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-01T09:39:26.463
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 7 seconds.

Event[1923]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T19:22:03.795
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1924]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-01-31T19:22:03.900
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[1925]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T19:22:08.660
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1926]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-01-31T19:22:08.660
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[1927]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-01-31T19:22:08.867
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?01T01:22:08.867716000Z.

Event[1928]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-01T09:39:18.637
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?01T15:39:18.495043400Z.

Event[1929]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[1930]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[1931]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[1932]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[1933]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[1934]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.637
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[1935]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-01T09:39:18.638
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[1936]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:22.336
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1937]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:22.336
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1938]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:22.337
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1939]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-01T09:39:22.668
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[1940]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:22.715
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1941]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:22.764
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1942]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-01T09:39:22.777
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[1943]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-01T09:39:22.947
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[1944]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-01T09:39:22.947
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[1945]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-01T09:39:23.115
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[1946]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-01T09:39:23.115
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[1947]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-01T09:39:23.469
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1948]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-01T09:39:23.472
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1949]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-01T09:39:23.473
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1950]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-01T09:39:23.473
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[1951]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-01T09:39:23.502
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[1952]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-01T09:39:23.610
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[1953]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-01T09:39:23.630
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[1954]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:24.151
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[1955]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-01T09:39:25.275
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[1956]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-01T09:39:25.370
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[1957]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-01T09:39:25.375
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[1958]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-01T09:39:27.213
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[1959]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[1960]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[1961]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[1962]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[1963]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[1964]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[1965]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-01T09:39:26.447
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[1966]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:26.499
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1967]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:26.502
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1968]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:26.504
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1969]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-01T09:39:26.506
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[1970]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-01T09:39:26.508
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[1971]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-01T09:39:26.518
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[1972]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-02-01T09:39:26.854
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[1973]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:39:26.979
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1974]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T09:39:27.026
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[1975]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:39:27.072
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1976]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-01T09:39:27.130
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[1977]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-01T09:39:27.193
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[1978]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-01T09:39:27.347
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[1979]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-01T09:39:28.491
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[1980]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-01T09:39:27.846
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[1981]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:39:28.392
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1982]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:39:28.394
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1983]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T09:39:28.494
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[1984]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-01T09:39:35.296
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[1985]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:40:55.688
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[1986]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T09:41:28.628
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[1987]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T09:41:40.386
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[1988]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T09:43:30.642
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[1989]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:46:01.459
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1990]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-01T09:46:11.216
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.ZuneVideo_10.16122.10291.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[1991]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:46:16.627
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Movies & TV

Event[1992]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:46:16.627
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Movies & TV

Event[1993]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T09:48:12.594
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[1994]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:49:45.552
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[1995]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:49:50.480
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1822.0)

Event[1996]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:49:56.177
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1822.0)

Event[1997]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-01T09:49:56.177
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1822.0)

Event[1998]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-01T09:54:29.217
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[1999]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T10:32:33.866
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[2000]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-01T11:00:01.797
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2001]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-01T11:02:01.822
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2002]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-01T12:00:00.479
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 8441 seconds.

Event[2003]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T12:49:43.557
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[2004]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T13:22:43.595
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 3 time(s) since it was last initialized.

Event[2005]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T13:32:43.559
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 4 time(s) since it was last initialized.

Event[2006]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T13:54:43.561
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 5 time(s) since it was last initialized.

Event[2007]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T14:04:43.576
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 6 time(s) since it was last initialized.

Event[2008]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T14:31:43.585
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 7 time(s) since it was last initialized.

Event[2009]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T15:31:43.593
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 8 time(s) since it was last initialized.

Event[2010]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T16:17:43.603
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 9 time(s) since it was last initialized.

Event[2011]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T16:27:43.597
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 10 time(s) since it was last initialized.

Event[2012]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T17:56:43.556
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 11 time(s) since it was last initialized.

Event[2013]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T19:42:43.569
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 12 time(s) since it was last initialized.

Event[2014]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T19:55:43.595
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 13 time(s) since it was last initialized.

Event[2015]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T21:41:43.593
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 14 time(s) since it was last initialized.

Event[2016]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T22:20:43.581
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 15 time(s) since it was last initialized.

Event[2017]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-01T22:31:43.578
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 16 time(s) since it was last initialized.

Event[2018]:
  Log Name: System
  Source: User32
  Date: 2017-02-01T22:57:16.558
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2019]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-01T22:57:20.470
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2020]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-01T22:57:19.909
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2021]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-01T22:57:20.457
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2022]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-01T22:57:20.484
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2023]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T11:33:58.311
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2024]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T11:33:58.311
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2025]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T11:33:58.311
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[2026]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-01T22:57:20.570
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2027]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-01T22:57:20.629
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2028]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-01T22:57:25.430
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2029]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-01T22:57:25.430
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2030]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-01T22:57:25.719
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?02T04:57:25.719518600Z.

Event[2031]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T11:33:51.493
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?02T17:33:51.341673300Z.

Event[2032]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2033]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2034]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2035]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2036]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2037]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2038]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T11:33:51.494
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2039]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:55.220
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2040]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:55.220
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2041]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:55.220
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2042]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T11:33:55.576
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2043]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:55.623
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2044]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:55.672
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2045]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-02T11:33:55.685
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2046]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-02T11:33:55.852
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2047]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-02T11:33:55.852
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2048]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T11:33:56.025
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2049]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-02T11:33:56.030
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2050]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T11:33:56.384
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2051]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T11:33:56.387
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2052]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T11:33:56.388
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2053]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T11:33:56.388
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2054]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T11:33:56.404
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2055]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T11:33:56.513
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2056]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T11:33:56.533
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2057]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T11:33:56.539
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \Device\HarddiskVolume3\Boot\BCD was cleared updating 283 keys and creating 14 modified pages.

Event[2058]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:57.063
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2059]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-02T11:33:57.946
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2060]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-02T11:33:58.044
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2061]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-02T11:33:58.050
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2062]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2063]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2064]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2065]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2066]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2067]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2068]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T11:33:58.253
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2069]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:58.276
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2070]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:58.302
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2071]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:58.304
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2072]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T11:33:58.306
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2073]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-02T11:33:58.331
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2074]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-02T11:33:58.342
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2075]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T11:33:58.671
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2076]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T11:33:58.671
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2077]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-02T11:33:59.954
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2078]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-02T11:34:00.430
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2079]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-02T11:33:59.525
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2080]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-02-02T11:33:59.796
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2081]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T11:33:59.860
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2082]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T11:33:59.889
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2083]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-02T11:33:59.905
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2084]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T11:33:59.977
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2085]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T11:34:00.617
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2086]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T11:34:00.817
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2087]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T11:34:00.819
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2088]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-02T11:34:07.980
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2089]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T16:22:39.645
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?02T22:22:39.495174800Z.

Event[2090]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2091]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was false. The last boot's success status was true.

Event[2092]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2093]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2094]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2095]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2096]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-02T16:22:39.645
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2097]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T16:22:46.115
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2098]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T16:22:46.115
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2099]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T16:22:46.115
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[2100]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:43.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2101]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:43.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2102]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:43.369
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2103]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T16:22:43.889
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2104]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:43.937
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2105]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:43.985
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2106]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-02T16:22:43.997
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Event[2107]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-02T16:22:43.998
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2108]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-02T16:22:44.085
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2109]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-02T16:22:44.085
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2110]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-02T16:22:44.225
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2111]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T16:22:44.359
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2112]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T16:22:44.580
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2113]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T16:22:44.582
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2114]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T16:22:44.583
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2115]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-02T16:22:44.583
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2116]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T16:22:44.780
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2117]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T16:22:44.883
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2118]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-02T16:22:44.903
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2119]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-02T16:22:45.774
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2120]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-02T16:22:45.870
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2121]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-02T16:22:45.874
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2122]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:46.133
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2123]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:46.136
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2124]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:46.139
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2125]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-02T16:22:46.141
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2126]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.131
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2127]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-02T16:22:46.156
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2128]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-02T16:22:46.168
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2129]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2130]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2131]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2132]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2133]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2134]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2135]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-02T16:22:46.303
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2136]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:22:46.480
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2137]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:22:46.480
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2138]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-02T16:22:48.033
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2139]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-02T16:22:47.718
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2140]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:22:47.860
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2141]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T16:22:47.950
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2142]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-02T16:22:47.974
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2143]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-02-02T16:22:47.993
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2144]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T16:22:48.077
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2145]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-02T16:22:48.490
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2146]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-02T16:22:48.500
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[2147]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:22:48.497
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2148]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:22:48.499
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[2149]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:22:48.500
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[2150]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:22:48.523
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2151]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:49.043
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0001 with the following status: 0.

Event[2152]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:22:49.714
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2153]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:22:49.741
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2154]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:52.030
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0001 with the following status: 0x0.

Event[2155]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:52.399
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0301 with the following status: 0.

Event[2156]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-02T16:22:55.794
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2157]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:56.778
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0301 with the following status: 0x0.

Event[2158]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:57.020
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0101 with the following status: 0.

Event[2159]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:59.305
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0101 with the following status: 0x0.

Event[2160]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:22:59.494
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service NVHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0201 with the following status: 0.

Event[2161]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:23:01.726
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvhda.inf_amd64_a745ecd308542068\nvhda.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10DE&DEV_0014&SUBSYS_10DE0101&REV_1001\5&36B425FB&0&0201 with the following status: 0x0.

Event[2162]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:23:14.442
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvlddmkm for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&3834D97&0&0008 with the following status: 0.

Event[2163]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-02T16:24:36.811
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nv_dispi.inf_amd64_02838dee03d82b94\nv_dispi.inf for Device Instance ID PCI\VEN_10DE&DEV_0F00&SUBSYS_26393842&REV_A1\4&3834D97&0&0008 with the following status: 0x0.

Event[2164]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:24:48.524
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2165]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:24:57.867
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2166]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:25:01.078
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2167]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-02T16:25:46.448
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2168]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:25:47.700
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2169]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:02.310
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2170]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:02.310
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2171]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:02.310
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2172]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:18.026
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2173]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:23.241
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1948.0)

Event[2174]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T16:26:26.061
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.WindowsCamera_2016.1215.40.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[2175]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:28.169
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.1948.0)

Event[2176]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:28.169
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Windows Camera

Event[2177]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:26:28.169
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Windows Camera

Event[2178]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-02T16:26:32.282
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2179]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T16:26:59.369
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\microsoft.windowscommunicationsapps_17.7830.42257.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[2180]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T16:27:00.749
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.Office.OneNote_17.7766.57821.0_x64__8wekyb3d8bbwe\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[2181]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:27:01.120
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Mail and Calendar

Event[2182]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:27:01.120
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Mail and Calendar

Event[2183]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:27:01.120
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: OneNote

Event[2184]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-02T16:27:06.580
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: OneNote

Event[2185]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:27:50.233
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2186]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-02T16:31:27.034
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2187]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-02T17:11:10.115
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[2188]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-02T19:16:10.104
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 2 time(s) since it was last initialized.

Event[2189]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-02T19:40:10.107
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 3 time(s) since it was last initialized.

Event[2190]:
  Log Name: System
  Source: User32
  Date: 2017-02-02T19:52:47.710
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2191]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-02T19:52:51.394
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2192]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-02T19:52:50.867
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2193]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-02T19:52:51.392
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2194]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-02T19:52:51.398
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2195]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T09:16:51.178
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2196]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T09:16:51.178
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2197]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T09:16:51.178
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6 seconds.

Event[2198]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T19:52:51.510
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2199]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-02T19:52:51.569
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2200]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-02T19:52:56.373
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2201]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-02T19:52:56.373
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2202]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-02T19:52:56.631
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?03T01:52:56.631356900Z.

Event[2203]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T09:16:44.657
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?03T15:16:44.495194400Z.

Event[2204]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2205]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2206]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2207]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2208]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2209]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2210]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T09:16:44.657
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2211]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:48.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2212]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:48.368
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2213]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:48.369
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2214]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T09:16:48.711
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2215]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:48.760
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2216]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:48.808
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2217]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-03T09:16:48.821
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2218]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-03T09:16:48.989
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2219]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T09:16:48.989
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2220]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T09:16:49.153
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2221]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-03T09:16:49.162
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2222]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T09:16:49.517
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2223]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T09:16:49.520
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2224]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T09:16:49.520
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2225]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T09:16:49.521
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2226]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T09:16:49.532
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2227]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T09:16:49.641
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2228]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T09:16:49.662
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2229]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:50.202
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2230]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-03T09:16:50.696
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2231]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-03T09:16:50.794
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2232]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-03T09:16:50.800
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2233]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2234]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2235]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2236]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2237]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2238]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2239]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T09:16:51.116
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2240]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:51.161
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2241]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:51.164
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2242]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:51.166
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2243]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T09:16:51.168
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2244]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-03T09:16:51.193
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2245]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-03T09:16:51.204
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2246]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:16:51.543
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2247]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:16:51.543
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2248]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-03T09:16:52.969
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2249]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-03T09:16:52.612
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2250]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-03T09:16:53.625
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2251]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:16:52.770
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2252]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-03T09:16:52.885
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2253]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T09:16:52.896
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2254]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-02-03T09:16:52.923
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2255]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T09:16:53.023
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2256]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:16:53.633
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2257]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:16:53.723
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2258]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:16:53.723
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2259]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:16:53.727
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2260]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-03T09:17:00.729
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2261]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:18:53.756
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2262]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T09:19:05.670
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2263]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:20:55.767
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2264]:
  Log Name: System
  Source: Microsoft-Windows-NDIS
  Date: 2017-02-03T09:23:29.756
  Event ID: 10400
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The network interface "Broadcom 802.11ac Network Adapter" has begun resetting.  There will be a momentary disruption in network connectivity while the hardware resets.
Reason: The network driver detected that its hardware has stopped responding to commands.
This network interface has reset 1 time(s) since it was last initialized.

Event[2265]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:24:52.257
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2266]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T09:26:55.052
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2267]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-03T09:31:54.752
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2268]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T10:34:32.568
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume ?? (\Device\HarddiskVolumeShadowCopy3) is healthy.  No action is needed.

Event[2269]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:33.916
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lynxpointsystem.inf_amd64_cd1e518d883ecdfe\lynxpointsystem.inf for Device Instance ID PCI\VEN_8086&DEV_8C10&SUBSYS_85341043&REV_D4\3&11583659&0&E0 with the following status: 0x0.

Event[2270]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:37.355
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lynxpointsystem.inf_amd64_cd1e518d883ecdfe\lynxpointsystem.inf for Device Instance ID PCI\VEN_8086&DEV_8C12&SUBSYS_85341043&REV_D4\3&11583659&0&E1 with the following status: 0x0.

Event[2271]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T10:34:37.834
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2272]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T10:34:42.073
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2273]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:42.149
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lynxpointsystem.inf_amd64_cd1e518d883ecdfe\lynxpointsystem.inf for Device Instance ID PCI\VEN_8086&DEV_8C16&SUBSYS_85341043&REV_D4\3&11583659&0&E3 with the following status: 0x0.

Event[2274]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:42.437
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lynxpointsystem.inf_amd64_cd1e518d883ecdfe\lynxpointsystem.inf for Device Instance ID PCI\VEN_8086&DEV_8C22&SUBSYS_85341043&REV_04\3&11583659&0&FB with the following status: 0x0.

Event[2275]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:42.765
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver lynxpointsystem.inf_amd64_cd1e518d883ecdfe\lynxpointsystem.inf for Device Instance ID PCI\VEN_8086&DEV_8C44&SUBSYS_85341043&REV_04\3&11583659&0&F8 with the following status: 0x0.

Event[2276]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-03T10:34:45.526
  Event ID: 4
  Task: N/A
  Level: Warning
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Intel(R) Management Engine Interface is being disabled.

Event[2277]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-03T10:34:45.597
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2278]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:34:45.601
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver heci.inf_amd64_f200e0c445085ecf\heci.inf for Device Instance ID PCI\VEN_8086&DEV_8C3A&SUBSYS_85341043&REV_04\3&11583659&0&B0 with the following status: 0x0.

Event[2279]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:35:37.731
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service bcbtums for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[2280]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:35:37.733
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service btwampfl for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[2281]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:35:37.739
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BTHUSB for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[2282]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:35:37.845
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BTHPORT for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0.

Event[2283]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:35:38.145
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bcbtums.inf_amd64_216392b751058a5f\bcbtums.inf for Device Instance ID USB\VID_0B05&PID_17CF\240A6438E79A with the following status: 0x0.

Event[2284]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T10:35:38.147
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2285]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:36:19.012
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver rt640x64.inf_amd64_1e0fbcfa6e9c8787\rt640x64.inf for Device Instance ID PCI\VEN_10EC&DEV_8168&SUBSYS_859E1043&REV_11\6&EB089EB&0&002800E3 with the following status: 0x0.

Event[2286]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T10:39:22.329
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  BCMWL63A
Service File Name:  \SystemRoot\system32\DRIVERS\bcmwl63a.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[2287]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:22.331
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service BCMWL63A for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0.

Event[2288]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:22.333
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service vwifibus for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0.

Event[2289]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:22.782
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver bcmwdi.inf_amd64_af92a87ae4f5939e\bcmwdi.inf for Device Instance ID PCI\VEN_14E4&DEV_43B1&SUBSYS_855C1043&REV_03\6&3B59F0C5&0&003800E3 with the following status: 0x0.

Event[2290]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T10:39:22.783
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2291]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T10:39:22.826
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2292]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:22.883
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver netvwifimp.inf_amd64_389d3e2956b38173\netvwifimp.inf for Device Instance ID {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_WFD\7&1353AC59&0&12 with the following status: 0x0.

Event[2293]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T10:39:30.758
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Intel(R) PRO/1000 PCI Express Network Connection Driver D
Service File Name:  \SystemRoot\system32\DRIVERS\e1d65x64.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[2294]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:30.759
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service e1dexpress for Device Instance ID PCI\VEN_8086&DEV_153B&SUBSYS_859F1043&REV_04\3&11583659&0&C8 with the following status: 0.

Event[2295]:
  Log Name: System
  Source: e1iexpress
  Date: 2017-02-03T10:39:30.894
  Event ID: 27
  Task: N/A
  Level: Warning
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link is disconnected.


Event[2296]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T10:39:31.086
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  Nal Service 
Service File Name:  C:\WINDOWS\system32\Drivers\iqvw64e.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[2297]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-03T10:39:31.224
  Event ID: 27
  Task: N/A
  Level: Warning
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link is disconnected.


Event[2298]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T10:39:31.765
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver e1d65x64.inf_amd64_2de580a425dabd06\e1d65x64.inf for Device Instance ID PCI\VEN_8086&DEV_153B&SUBSYS_859F1043&REV_04\3&11583659&0&C8 with the following status: 0x0.

Event[2299]:
  Log Name: System
  Source: Tcpip
  Date: 2017-02-03T10:39:33.759
  Event ID: 4199
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system detected an address conflict for IP address 2602:30a:c042:c710::3ea with the system having network hardware address A4-5D-36-3F-CC-A7. Network operations on this system may be disrupted as a result.

Event[2300]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-03T10:39:34.673
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2301]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-03T10:39:39.820
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[2302]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-03T10:39:43.555
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name tprnjosasxt timed out after none of the configured DNS servers responded.

Event[2303]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:05.911
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service IntcAzAudAddService for Device Instance ID HDAUDIO\FUNC_01&VEN_10EC&DEV_0900&SUBSYS_1043855F&REV_1000\4&31483CB2&0&0001 with the following status: 0.

Event[2304]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:07.354
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\audiodg.exe with process id 6516 stopped the removal or ejection for the device HDAUDIO\FUNC_01&VEN_10EC&DEV_0900&SUBSYS_1043855F&REV_1000\4&31483cb2&0&0001.

Event[2305]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:17.938
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver hdxrt4.inf_amd64_d7b8a4a7867ecd91\hdxrt4.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_10EC&DEV_0900&SUBSYS_1043855F&REV_1000\4&31483CB2&0&0001 with the following status: 0x0.

Event[2306]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:20.767
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service nvvad_WaveExtensible for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0.

Event[2307]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:20.855
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver nvvad.inf_amd64_f272521b2523b1fa\nvvad.inf for Device Instance ID ROOT\UNNAMED_DEVICE\0000 with the following status: 0x0.

Event[2308]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:11:23.721
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  asstahci64
Service File Name:  System32\drivers\asstahci64.sys
Service Type:  kernel mode driver
Service Start Type:  boot start
Service Account:  

Event[2309]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:27.822
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver asstahci64.inf_amd64_a991f74c4d02de11\asstahci64.inf for Device Instance ID PCI\VEN_1B21&DEV_0612&SUBSYS_858D1043&REV_01\4&1933C71D&0&00E1 with the following status: 0x0.

Event[2310]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:32.188
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver asstahci64.inf_amd64_a991f74c4d02de11\asstahci64.inf for Device Instance ID PCI\VEN_1B21&DEV_0612&SUBSYS_858D1043&REV_01\6&366007D&0&004800E3 with the following status: 0x0.

Event[2311]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:11:38.780
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  iaStorA
Service File Name:  System32\drivers\iaStorA.sys
Service Type:  kernel mode driver
Service Start Type:  boot start
Service Account:  

Event[2312]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application System with process id 4 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2313]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\smss.exe with process id 368 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2314]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 380 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2315]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 528 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2316]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\dwm.exe with process id 544 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2317]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\csrss.exe with process id 552 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2318]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\wininit.exe with process id 652 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2319]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\csrss.exe with process id 660 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2320]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\services.exe with process id 728 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2321]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\lsass.exe with process id 736 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2322]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 844 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2323]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 908 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2324]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\winlogon.exe with process id 1004 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2325]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1032 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2326]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\WUDFHost.exe with process id 1140 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2327]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1208 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2328]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe with process id 1252 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2329]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1332 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2330]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1344 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2331]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe with process id 1388 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2332]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\dasHost.exe with process id 1412 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2333]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Display\nvxdsync.exe with process id 1604 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2334]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\SearchIndexer.exe with process id 1644 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2335]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Realtek\Audio\HDA\RAVBg64.exe with process id 1652 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2336]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1716 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2337]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 1788 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2338]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Any Password Pro\apwp.exe with process id 1860 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2339]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2108 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2340]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\spoolsv.exe with process id 2168 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2341]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2372 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2342]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe with process id 2384 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2343]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe with process id 2392 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2344]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2408 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2345]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\BtwRSupportService.exe with process id 2424 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2346]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2468 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2347]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe with process id 2480 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2348]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\IPROSetMonitor.exe with process id 2496 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2349]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\escsvc64.exe with process id 2504 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2350]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe with process id 2512 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2351]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2560 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2352]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\mqsvc.exe with process id 2588 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2353]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe with process id 2696 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2354]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe with process id 2712 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2355]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 2836 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2356]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe with process id 2856 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2357]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\TeamViewer\TeamViewer_Service.exe with process id 2876 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2358]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe with process id 3332 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2359]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe with process id 3668 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2360]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe with process id 3900 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2361]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe with process id 3916 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2362]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\sihost.exe with process id 4040 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2363]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 4140 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2364]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\wbem\WmiPrvSE.exe with process id 4172 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2365]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Windows Media Player\wmpnetwk.exe with process id 4188 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2366]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 4376 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2367]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\SysWOW64\wowreg32.exe with process id 4440 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2368]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\taskhostw.exe with process id 4536 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2369]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Drive Speedometer\Drive_Speedometer.exe with process id 4564 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2370]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\CleanMem\Mini_Monitor.exe with process id 4576 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2371]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\RuntimeBroker.exe with process id 4920 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2372]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe with process id 4988 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2373]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 5020 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2374]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe with process id 5180 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2375]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Windows Defender\NisSrv.exe with process id 5296 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2376]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\wlanext.exe with process id 5396 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2377]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe with process id 5404 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2378]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Windows Defender\MSASCuiL.exe with process id 5520 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2379]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\SettingSyncHost.exe with process id 5576 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2380]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 5724 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2381]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\explorer.exe with process id 5732 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2382]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 5752 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2383]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 6172 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2384]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 6196 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2385]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\audiodg.exe with process id 6516 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2386]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.152.0_x64__kzf8qxf38zg5c\SkypeHost.exe with process id 6636 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2387]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Easeware\DriverEasy\DriverEasy.exe with process id 6696 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2388]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\SysWOW64\wowreg32.exe with process id 6712 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2389]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Skype\Phone\Skype.exe with process id 6924 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2390]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\ImmersiveControlPanel\SystemSettings.exe with process id 7316 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2391]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.WindowsStore_11610.1001.25.0_x64__8wekyb3d8bbwe\WinStore.App.exe with process id 7512 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2392]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 8036 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2393]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe with process id 8648 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2394]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\conhost.exe with process id 8744 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2395]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\NVIDIA Corporation\Display\nvtray.exe with process id 8840 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2396]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\WizMouse\WizMouse.exe with process id 8900 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2397]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe with process id 9080 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2398]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9244 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2399]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe with process id 9248 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2400]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Common Files\Java\Java Update\jusched.exe with process id 9272 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2401]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9276 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2402]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9284 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2403]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9300 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2404]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\UltraMon\UltraMonUiAcc.exe with process id 9308 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2405]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe with process id 9384 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2406]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\UltraMon\UltraMon.exe with process id 9400 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2407]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Drive\googledrivesync.exe with process id 9568 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2408]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Drive\googledrivesync.exe with process id 9588 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2409]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\spool\drivers\x64\3\E_YATIPAE.EXE with process id 9608 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2410]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\fontdrvhost.exe with process id 9648 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2411]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe with process id 9704 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2412]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9752 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2413]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9784 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2414]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9792 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2415]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9872 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2416]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 9880 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2417]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe with process id 9956 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2418]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 10016 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2419]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Google\Chrome\Application\chrome.exe with process id 10020 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2420]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\drvinst.exe with process id 10084 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2421]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe with process id 10120 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2422]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\svchost.exe with process id 10164 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2423]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe with process id 10592 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2424]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe with process id 10708 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2425]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe with process id 10752 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2426]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:11:39.020
  Event ID: 225
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application \Device\HarddiskVolume4\Windows\System32\ApplicationFrameHost.exe with process id 11188 stopped the removal or ejection for the device PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA.

Event[2427]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:39.026
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver iaahcic.inf_amd64_263f3b89cfbc4226\iaahcic.inf for Device Instance ID PCI\VEN_8086&DEV_8C02&SUBSYS_85341043&REV_04\3&11583659&0&FA with the following status: 0x0.

Event[2428]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:40.245
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver haswellsystem.inf_amd64_519ef4c07e556e82\haswellsystem.inf for Device Instance ID PCI\VEN_8086&DEV_0C00&SUBSYS_85341043&REV_06\3&11583659&0&00 with the following status: 0x0.

Event[2429]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:11:41.377
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver haswellsystem.inf_amd64_519ef4c07e556e82\haswellsystem.inf for Device Instance ID PCI\VEN_8086&DEV_0C01&SUBSYS_85341043&REV_06\3&11583659&0&08 with the following status: 0x0.

Event[2430]:
  Log Name: System
  Source: nvlddmkm
  Date: 2017-02-03T11:11:43.336
  Event ID: 14
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
N/A

Event[2431]:
  Log Name: System
  Source: User32
  Date: 2017-02-03T11:15:18.816
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\shutdown.exe (COOLBLOSSOM13) has initiated the restart of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: No title for this reason could be found
 Reason Code: 0x800000ff
 Shutdown Type: restart
 Comment: 

Event[2432]:
  Log Name: System
  Source: Application Popup
  Date: 2017-02-03T11:15:20.851
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Application popup: explorer.exe - Application Error : The instruction at 0x00000000742CB00C referenced memory at 0x00000000742CB00C. The memory could not be written.

Click on OK to terminate the program

Event[2433]:
  Log Name: System
  Source: User32
  Date: 2017-02-03T11:15:38.535
  Event ID: 1073
  Task: N/A
  Level: Warning
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The attempt by user CoolBlossom13\Roberto to restart/shutdown computer COOLBLOSSOM13 failed

Event[2434]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:15:44.209
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2435]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-03T11:15:46.951
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2436]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T11:15:47.485
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2437]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-03T11:15:47.496
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2438]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-03T11:15:47.497
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2439]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T11:15:47.602
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2440]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T11:16:15.039
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2441]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T11:16:15.039
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2442]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T11:16:15.039
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 11 seconds.

Event[2443]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T11:15:47.607
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2444]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-03T11:15:52.457
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2445]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T11:15:53.045
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?03T17:15:53.045021200Z.

Event[2446]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T11:16:03.659
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?03T17:16:03.495115400Z.

Event[2447]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2448]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2449]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2450]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2451]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2452]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2453]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-03T11:16:03.659
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2454]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:04.377
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2455]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:04.378
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2456]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:04.378
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2457]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T11:16:12.592
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2458]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:12.649
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2459]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:12.697
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2460]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-03T11:16:12.710
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2461]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-03T11:16:12.902
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2462]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-03T11:16:12.902
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2463]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T11:16:13.057
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2464]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-03T11:16:13.083
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2465]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T11:16:13.273
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2466]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T11:16:13.276
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2467]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T11:16:13.277
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2468]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-03T11:16:13.277
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2469]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T11:16:13.461
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2470]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T11:16:13.561
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2471]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-03T11:16:13.573
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2472]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:14.094
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2473]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-03T11:16:14.601
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2474]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-03T11:16:14.691
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2475]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-03T11:16:14.697
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2476]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2477]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2478]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2479]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2480]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2481]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2482]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-03T11:16:15.023
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2483]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:15.051
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2484]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:15.080
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2485]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:15.082
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2486]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-03T11:16:15.084
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2487]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-03T11:16:15.089
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2488]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-03T11:16:15.098
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2489]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T11:16:15.859
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2490]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:16:15.873
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2491]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T11:16:15.940
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2492]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-03T11:16:16.139
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2493]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-03T11:16:16.732
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2494]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-03T11:16:16.067
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2495]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-03T11:16:16.136
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2496]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-03T11:16:16.311
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2497]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T11:16:16.904
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2498]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T11:16:16.904
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2499]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:16:17.165
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2500]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T11:16:17.227
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2501]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-03T11:16:24.635
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2502]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:18:17.289
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2503]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T11:18:28.902
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2504]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:20:19.301
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2505]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-03T11:24:55.484
  Event ID: 24576
  Task: Driver Installation
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Drivers were successfully installed for device WPD Device.

Event[2506]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-03T11:24:55.505
  Event ID: 24577
  Task: Driver Post-Install Configuration
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Media player and imaging program compatibility layers were successfully registered for device %1. Layer bits %2 were requested, layer bits %3 were registered.

Event[2507]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-03T11:24:55.505
  Event ID: 24579
  Task: Driver Post-Install Configuration
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Autoplay registration was skipped for device %1.

Event[2508]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-03T11:24:55.394
  Event ID: 10000
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A driver package which uses user-mode driver framework version 2.19.0 is being installed on device SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_PNY&PROD_USB_2.0_FD&REV_8.07#201312072104317500DB&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}.

Event[2509]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-03T11:24:55.396
  Event ID: 10001
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The UMDF service WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) was installed.  It requires framework version 2.19.0 or higher.

Event[2510]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-03T11:24:55.400
  Event ID: 10100
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver package installation has succeeded.

Event[2511]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:24:55.418
  Event ID: 7045
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A service was installed in the system.

Service Name:  WUDFWpdFs
Service File Name:  \SystemRoot\system32\DRIVERS\WUDFRd.sys
Service Type:  kernel mode driver
Service Start Type:  demand start
Service Account:  

Event[2512]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:24:55.420
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service WUDFWpdFs for Device Instance ID SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_PNY&PROD_USB_2.0_FD&REV_8.07#201312072104317500DB&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B} with the following status: 0.

Event[2513]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-03T11:24:55.515
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver wpdfs.inf_amd64_4b4cfcfa114bdc22\wpdfs.inf for Device Instance ID SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_PNY&PROD_USB_2.0_FD&REV_8.07#201312072104317500DB&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B} with the following status: 0x0.

Event[2514]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:24:58.054
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2515]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T11:26:58.046
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2516]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:28:17.881
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2517]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:30:38.647
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2518]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-03T11:31:17.938
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2519]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T11:38:25.900
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2520]:
  Log Name: System
  Source: BROWSER
  Date: 2017-02-03T11:52:19.589
  Event ID: 8033
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The browser has forced an election on network \Device\NetBT_Tcpip_{4CB94F8D-A8E9-46D4-B0BE-5775E5EA00E2} because a master browser was stopped.

Event[2521]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-03T11:52:30.650
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name win10.ipv6.microsoft.com. timed out after none of the configured DNS servers responded.

Event[2522]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-03T11:52:32.744
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name 369-trouter-eus2-a.drip.trouter.io timed out after none of the configured DNS servers responded.

Event[2523]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-03T11:52:43.703
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name ipv4only.arpa timed out after none of the configured DNS servers responded.

Event[2524]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T12:00:00.062
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 2636 seconds.

Event[2525]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T13:16:46.591
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2526]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T13:16:52.819
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2016.0)

Event[2527]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T13:16:58.118
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2016.0)

Event[2528]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T13:38:59.716
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2529]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T13:40:59.751
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2530]:
  Log Name: System
  Source: Display
  Date: 2017-02-03T15:45:04.674
  Event ID: 4107
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A caller specified the SDC_FORCE_MODE_ENUMERATION flag in a call to the SetDisplayConfig() API

Event[2531]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-03T15:47:12.286
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2532]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T15:49:12.320
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2533]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-03T16:53:20.211
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider NtpClient is currently receiving valid time data from time.nist.gov,0x9 (ntp.m|0x9|[::]:123->[2610:20:6f15:15::27]:123).

Event[2534]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-03T16:53:20.215
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time service is now synchronizing the system time with the time source time.nist.gov,0x9 (ntp.m|0x9|[::]:123->[2610:20:6f15:15::27]:123).

Event[2535]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-03T16:53:36.218
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time service is now synchronizing the system time with the time source time.nist.gov,0x9 (ntp.m|0x9|0.0.0.0:123->216.229.0.179:123).

Event[2536]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T17:10:55.083
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2537]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T17:11:22.013
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat was cleared updating 171 keys and creating 30 modified pages.

Event[2538]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T17:11:56.367
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\king.com.CandyCrushSodaSaga_1.82.900.0_x86__kgqvnymyfvs32\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[2539]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T17:12:01.631
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Candy Crush Soda Saga

Event[2540]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-03T17:12:01.631
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Candy Crush Soda Saga

Event[2541]:
  Log Name: System
  Source: User32
  Date: 2017-02-03T17:59:04.631
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2542]:
  Log Name: System
  Source: Application Popup
  Date: 2017-02-03T17:59:07.964
  Event ID: 26
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Application popup: explorer.exe - Application Error : The instruction at 0x000000005BB3B00C referenced memory at 0x000000005BB3B00C. The memory could not be written.

Click on OK to terminate the program

Event[2543]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T17:59:34.022
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server App.AppXryc2qd338f5728r9gzzazav8206ba77s.mca did not register with DCOM within the required timeout.

Event[2544]:
  Log Name: System
  Source: User32
  Date: 2017-02-03T18:00:12.962
  Event ID: 1073
  Task: N/A
  Level: Warning
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The attempt by user CoolBlossom13\Roberto to restart/shutdown computer COOLBLOSSOM13 failed

Event[2545]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T18:00:28.486
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat was cleared updating 4 keys and creating 2 modified pages.

Event[2546]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T18:00:28.517
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat was cleared updating 466 keys and creating 45 modified pages.

Event[2547]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T18:00:34.240
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server App.AppXryc2qd338f5728r9gzzazav8206ba77s.mca did not register with DCOM within the required timeout.

Event[2548]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-03T18:00:34.240
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca did not register with DCOM within the required timeout.

Event[2549]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-03T18:00:34.776
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2550]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-03T18:00:35.286
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2551]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T18:00:35.266
  Event ID: 1
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Time
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The system time has changed to ?2017?-?02?-?04T00:00:35.277000000Z from ?2017?-?02?-?04T00:00:35.288510500Z.

Change Reason: An application or system component changed the time.

Event[2552]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-03T18:00:35.279
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2553]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-03T18:00:35.289
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2554]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:42:06.217
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2555]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:42:06.217
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2556]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:42:06.217
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 11 seconds.

Event[2557]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T18:00:35.390
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2558]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-03T18:00:35.394
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2559]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-03T18:00:40.244
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2560]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-03T18:00:40.244
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2561]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-03T18:00:40.486
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?04T00:00:40.486133000Z.

Event[2562]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:41:54.659
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?04T16:41:54.495089000Z.

Event[2563]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.659
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2564]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.659
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2565]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.660
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2566]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.660
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2567]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.660
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2568]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.660
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2569]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:41:54.660
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2570]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:41:55.407
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2571]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:41:55.408
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2572]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:41:55.408
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2573]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:42:03.644
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2574]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:03.700
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2575]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:03.750
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2576]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-04T10:42:03.763
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2577]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-04T10:42:03.954
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2578]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-04T10:42:03.954
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2579]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:42:04.103
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2580]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-04T10:42:04.225
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2581]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:42:04.422
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2582]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:42:04.425
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2583]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:42:04.425
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2584]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:42:04.426
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2585]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:42:04.456
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2586]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:42:04.557
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2587]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:42:04.568
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2588]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:05.654
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2589]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-04T10:42:05.763
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2590]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-04T10:42:05.852
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2591]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-04T10:42:05.857
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2592]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-04T10:42:07.002
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2593]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:06.230
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2594]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2595]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2596]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2597]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2598]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2599]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2600]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:42:06.217
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2601]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:06.258
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2602]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:06.261
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2603]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:42:06.263
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2604]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-04T10:42:06.268
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2605]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-04T10:42:06.278
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2606]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:42:06.367
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\bbimigrate\BBI was cleared updating 783 keys and creating 153 modified pages.

Event[2607]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:42:06.649
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2608]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-04T10:42:06.662
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2609]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:45:07.659
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?04T16:45:07.495117400Z.

Event[2610]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2611]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was false. The last boot's success status was true.

Event[2612]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2613]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2614]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2615]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2616]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-04T10:45:07.659
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2617]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:08.361
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2618]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:08.361
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2619]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:08.361
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2620]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:45:19.621
  Event ID: 6008
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The previous system shutdown at 10:42:06 AM on ?2/?4/?2017 was unexpected.

Event[2621]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:45:19.621
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2622]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:45:19.621
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2623]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T10:45:19.621
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 12 seconds.

Event[2624]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:45:16.860
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2625]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:16.915
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2626]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:16.964
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2627]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-04T10:45:16.977
  Event ID: 41
  Task: N/A
  Level: Critical
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.

Event[2628]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-04T10:45:16.977
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2629]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-04T10:45:17.167
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2630]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-04T10:45:17.167
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2631]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-04T10:45:17.334
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2632]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:45:17.383
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2633]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:45:17.531
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2634]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:45:17.534
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2635]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:45:17.534
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2636]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-04T10:45:17.535
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2637]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:45:17.778
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2638]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:45:17.880
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2639]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T10:45:17.892
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2640]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:18.498
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2641]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-04T10:45:19.031
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2642]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-04T10:45:19.118
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2643]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-04T10:45:19.122
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2644]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2645]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2646]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2647]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2648]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2649]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2650]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-04T10:45:19.621
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2651]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:19.662
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2652]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:19.668
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2653]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:19.671
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2654]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-04T10:45:19.674
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2655]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-04T10:45:19.681
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2656]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-04T10:45:19.694
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2657]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-04T10:45:20.321
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2658]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:20.086
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2659]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:45:20.164
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2660]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:20.211
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2661]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-04T10:45:20.315
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2662]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-04T10:45:20.345
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2663]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-04T10:45:20.437
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2664]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-04T10:45:21.082
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2665]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-04T10:45:21.254
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2666]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-04T10:45:21.282
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[2667]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-04T10:45:21.176
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2668]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:45:21.259
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2669]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:45:21.279
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The UPnP Device Host service depends on the SSDP Discovery service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2670]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:21.280
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[2671]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:45:21.282
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Media Player Network Sharing Service service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[2672]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:21.385
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2673]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:21.556
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2674]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:45:21.561
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2675]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:45:26.706
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 17 keys and creating 2 modified pages.

Event[2676]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-04T10:45:29.058
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2677]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:45:29.903
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages.

Event[2678]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:45:29.982
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 35 keys and creating 4 modified pages.

Event[2679]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T10:45:30.780
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 13 keys and creating 2 modified pages.

Event[2680]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:47:21.262
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2681]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:47:30.188
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2682]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T10:47:33.472
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2683]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-04T10:49:07.083
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2684]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T10:50:20.890
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2685]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T11:13:05.833
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 6 keys and creating 1 modified pages.

Event[2686]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-04T11:54:39.584
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2687]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-04T11:54:39.584
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2080.0)

Event[2688]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-04T11:55:13.147
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2080.0)

Event[2689]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T12:00:00.626
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 4493 seconds.

Event[2690]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T12:22:55.947
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\C:\WINDOWS\System32\config\COMPONENTS was reorganized with a starting size of 52416512 bytes and an ending size of 52445184 bytes.

Event[2691]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:22:55.972
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[2692]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T12:22:56.724
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \SystemRoot\System32\config\DRIVERS was reorganized with a starting size of 6524928 bytes and an ending size of 6565888 bytes.

Event[2693]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T12:23:01.423
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\C:\WINDOWS\System32\SMI\Store\Machine\SCHEMA.DAT was reorganized with a starting size of 12537856 bytes and an ending size of 11837440 bytes.

Event[2694]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:23:01.660
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[2695]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-04T12:23:01.669
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume ?? (\Device\HarddiskVolumeShadowCopy4) is healthy.  No action is needed.

Event[2696]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:30:30.672
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[2697]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:34:03.331
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[2698]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:49:09.794
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[2699]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T12:53:07.053
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[2700]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T13:33:01.282
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[2701]:
  Log Name: System
  Source: Volsnap
  Date: 2017-02-04T13:33:25.830
  Event ID: 33
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The oldest shadow copy of volume C: was deleted to keep disk space usage for shadow copies of volume C: below the user defined limit.

Event[2702]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T13:57:18.362
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[2703]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T14:00:57.372
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from demand start to auto start.

Event[2704]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T14:11:15.731
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Windows Modules Installer service was changed from auto start to demand start.

Event[2705]:
  Log Name: System
  Source: Microsoft-Windows-UserModePowerService
  Date: 2017-02-04T15:17:43.115
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Process C:\Windows\explorer.exe (process ID:8500) reset policy scheme from {381B4222-F694-41F0-9685-FF5BB260DF2E} to {381B4222-F694-41F0-9685-FF5BB260DF2E}

Event[2706]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-04T17:37:56.602
  Event ID: 24576
  Task: Driver Installation
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Drivers were successfully installed for device WPD Device.

Event[2707]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-04T17:37:56.620
  Event ID: 24577
  Task: Driver Post-Install Configuration
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Media player and imaging program compatibility layers were successfully registered for device %1. Layer bits %2 were requested, layer bits %3 were registered.

Event[2708]:
  Log Name: System
  Source: Microsoft-Windows-WPDClassInstaller
  Date: 2017-02-04T17:37:56.621
  Event ID: 24579
  Task: Driver Post-Install Configuration
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Autoplay registration was skipped for device %1.

Event[2709]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-04T17:37:56.525
  Event ID: 10000
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
A driver package which uses user-mode driver framework version 2.19.0 is being installed on device SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_SMI&PROD_USB_DISK&REV_1100#AA330463000360182026&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}.

Event[2710]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-04T17:37:56.527
  Event ID: 10002
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The UMDF service WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) was upgraded.  It requires framework version 2.19.0 or higher.

Event[2711]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-04T17:37:56.530
  Event ID: 10100
  Task: Installation or update of device drivers.
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver package installation has succeeded.

Event[2712]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-04T17:37:56.538
  Event ID: 20003
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management has concluded the process to add Service WUDFWpdFs for Device Instance ID SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_SMI&PROD_USB_DISK&REV_1100#AA330463000360182026&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B} with the following status: 0.

Event[2713]:
  Log Name: System
  Source: Microsoft-Windows-UserPnp
  Date: 2017-02-04T17:37:56.631
  Event ID: 20001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Driver Management concluded the process to install driver wpdfs.inf_amd64_4b4cfcfa114bdc22\wpdfs.inf for Device Instance ID SWD\WPDBUSENUM\_??_USBSTOR#DISK&VEN_SMI&PROD_USB_DISK&REV_1100#AA330463000360182026&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B} with the following status: 0x0.

Event[2714]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-04T23:17:42.162
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2715]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T23:19:42.186
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2716]:
  Log Name: System
  Source: User32
  Date: 2017-02-04T23:20:19.368
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2717]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-04T23:20:20.399
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server App.AppXryc2qd338f5728r9gzzazav8206ba77s.mca did not register with DCOM within the required timeout.

Event[2718]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-04T23:20:24.893
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2719]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-04T23:20:24.361
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2720]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-04T23:20:24.903
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2721]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-04T23:20:24.912
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2722]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T03:41:21.706
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2723]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T03:41:21.706
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2724]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T03:41:21.706
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 14 seconds.

Event[2725]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-04T23:20:25.025
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2726]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-04T23:20:25.083
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2727]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-04T23:20:29.891
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2728]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-04T23:20:29.891
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2729]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-04T23:20:30.302
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?05T05:20:30.302680200Z.

Event[2730]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:07.848
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?05T09:41:07.495085200Z.

Event[2731]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2732]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2733]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2734]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2735]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2736]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2737]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T03:41:07.849
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2738]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:08.564
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2739]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:08.564
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2740]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:08.565
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2741]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T03:41:17.225
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2742]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:17.281
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2743]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:17.330
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2744]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T03:41:17.344
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2745]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-05T03:41:17.538
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2746]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-05T03:41:17.538
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2747]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T03:41:17.690
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2748]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-05T03:41:17.709
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2749]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T03:41:17.906
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2750]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T03:41:17.909
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2751]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T03:41:17.909
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2752]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T03:41:17.910
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2753]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T03:41:18.043
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2754]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T03:41:18.144
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2755]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T03:41:18.155
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2756]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:19.581
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \SystemRoot\System32\Config\SOFTWARE was reorganized with a starting size of 99627008 bytes and an ending size of 99540992 bytes.

Event[2757]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:19.678
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2758]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:20.673
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\DEFAULT was cleared updating 4020 keys and creating 282 modified pages.

Event[2759]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-05T03:41:21.195
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2760]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:21.220
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\SECURITY was cleared updating 100 keys and creating 5 modified pages.

Event[2761]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-05T03:41:21.288
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2762]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:21.289
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\SAM was cleared updating 73 keys and creating 7 modified pages.

Event[2763]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-05T03:41:21.294
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2764]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:21.374
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\ServiceProfiles\NetworkService\NTUSER.DAT was cleared updating 644 keys and creating 36 modified pages.

Event[2765]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-05T03:41:21.440
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2766]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:21.595
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \SystemRoot\System32\Config\BBI was cleared updating 719 keys and creating 140 modified pages.

Event[2767]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:21.601
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\ServiceProfiles\LocalService\NTUSER.DAT was cleared updating 643 keys and creating 37 modified pages.

Event[2768]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-05T03:41:22.305
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2769]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2770]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2771]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2772]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2773]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2774]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2775]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T03:41:21.628
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2776]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:21.647
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2777]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:21.673
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2778]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:21.675
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2779]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T03:41:21.677
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2780]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-05T03:41:21.731
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2781]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-05T03:41:21.741
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2782]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:41:22.065
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2783]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:41:22.097
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2784]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T03:41:22.159
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2785]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T03:41:22.200
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2786]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-05T03:41:22.307
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2787]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T03:41:22.372
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2788]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-05T03:41:22.784
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2789]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:22.937
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\ntuser.dat was cleared updating 7973 keys and creating 962 modified pages.

Event[2790]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:23.049
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\Users\Roberto\AppData\Local\Microsoft\Windows\UsrClass.dat was cleared updating 20485 keys and creating 2026 modified pages.

Event[2791]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T03:41:23.070
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\WINDOWS\AppCompat\Programs\Amcache.hve was cleared updating 10013 keys and creating 1551 modified pages.

Event[2792]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-05T03:41:23.762
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2793]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T03:41:23.771
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam
EhStorClass

Event[2794]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:41:23.913
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2795]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:41:23.915
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2796]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-05T03:41:31.239
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2797]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T03:43:23.896
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2798]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:43:32.842
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2799]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T03:45:25.888
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2800]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T03:45:37.056
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2801]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-05T03:56:24.358
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2802]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T04:44:05.893
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2803]:
  Log Name: System
  Source: User32
  Date: 2017-02-05T04:54:50.541
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2804]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T04:54:54.837
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2805]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-05T04:54:54.285
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2806]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-05T04:54:54.818
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2807]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-05T04:54:54.848
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2808]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T11:53:13.536
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2809]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T11:53:13.536
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2810]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T11:53:13.539
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 12 seconds.

Event[2811]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T04:54:54.940
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2812]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T04:54:54.945
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2813]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T04:54:59.795
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2814]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T04:54:59.795
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2815]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T04:55:00.092
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?05T10:55:00.092009200Z.

Event[2816]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T11:53:01.657
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?05T17:53:01.495058600Z.

Event[2817]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.657
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2818]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.657
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2819]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.658
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2820]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.658
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2821]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.658
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2822]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.658
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2823]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-05T11:53:01.658
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2824]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:02.360
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2825]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:02.361
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2826]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:02.361
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2827]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T11:53:11.027
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2828]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:11.082
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2829]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:11.132
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2830]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T11:53:11.146
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2831]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-05T11:53:11.337
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2832]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-05T11:53:11.337
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2833]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T11:53:11.499
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2834]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-05T11:53:11.506
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2835]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T11:53:11.702
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2836]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T11:53:11.705
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2837]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T11:53:11.706
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2838]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-05T11:53:11.706
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2839]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T11:53:11.886
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2840]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T11:53:11.987
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2841]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-05T11:53:11.998
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2842]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:12.520
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2843]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-05T11:53:13.017
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2844]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-05T11:53:13.108
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2845]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-05T11:53:13.114
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2846]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2847]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2848]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2849]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2850]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2851]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2852]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-05T11:53:13.433
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2853]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:13.480
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2854]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:13.507
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2855]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:13.510
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2856]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-05T11:53:13.512
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2857]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-05T11:53:13.551
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2858]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-05T11:53:13.562
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2859]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:53:13.891
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2860]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:53:13.954
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2861]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:53:14.001
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2862]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-05T11:53:14.110
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2863]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-05T11:53:14.930
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2864]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-05T11:53:14.045
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2865]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T11:53:14.108
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2866]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T11:53:14.208
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2867]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-05T11:53:14.523
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2868]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:53:14.917
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2869]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:53:15.052
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2870]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:53:15.098
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2871]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:53:15.109
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2872]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-05T11:53:15.345
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2873]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-05T11:53:23.040
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2874]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-05T11:53:27.052
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[2875]:
  Log Name: System
  Source: Microsoft-Windows-DNS-Client
  Date: 2017-02-05T11:53:29.055
  Event ID: 1014
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
Name resolution for the name wpad timed out after none of the configured DNS servers responded.

Event[2876]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:55:14.912
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2877]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-05T11:55:23.711
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2878]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:55:29.307
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2879]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:56:14.880
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2880]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-05T11:57:29.015
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2881]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-05T11:57:35.512
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2142.0)

Event[2882]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-05T11:57:40.835
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2142.0)

Event[2883]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T11:58:17.422
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2884]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T12:00:00.539
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 419 seconds.

Event[2885]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-05T12:00:44.212
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2886]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-05T12:08:17.399
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2887]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:27.155
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\WINDOWS\System32\config\SYSTEM was reorganized with a starting size of 21848064 bytes and an ending size of 21045248 bytes.

Event[2888]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:27.162
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\WINDOWS\System32\config\SYSTEM (TM: {EFC5489E-EBCB-11E6-AA2C-240A6438E79A}, RM: {EFC5489D-EBCB-11E6-AA2C-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[2889]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:27.236
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy3\WINDOWS\System32\config\DRIVERS (TM: {EFC548A0-EBCB-11E6-AA2C-240A6438E79A}, RM: {EFC5489F-EBCB-11E6-AA2C-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[2890]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:29.043
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{1D06BB37-8BB0-4FEE-B3FE-6D220EBF76A5} was reorganized with a starting size of 21848064 bytes and an ending size of 21045248 bytes.

Event[2891]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:29.194
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{B4E82479-4108-4655-8D3E-96C61AA47975} was cleared updating 73 keys and creating 7 modified pages.

Event[2892]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:29.380
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{C684726E-F8BC-4D5D-87ED-856E6C1BA45F} was cleared updating 100 keys and creating 5 modified pages.

Event[2893]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:30.834
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{DB2AB327-A2FC-4A54-BF52-2D80DF79FB35} was reorganized with a starting size of 12537856 bytes and an ending size of 11837440 bytes.

Event[2894]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:31.199
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{FED004E8-59D0-46A7-B6A6-3BD4E9D0296E} was cleared updating 4020 keys and creating 282 modified pages.

Event[2895]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:33.999
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{EBF7F7FA-6945-4FDD-8136-3CA70E2FD7FB} was reorganized with a starting size of 99627008 bytes and an ending size of 99696640 bytes.

Event[2896]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:36.650
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\SYSTEM was reorganized with a starting size of 21848064 bytes and an ending size of 20348928 bytes.

Event[2897]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:36.657
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\SYSTEM (TM: {EFC548C1-EBCB-11E6-AA2C-240A6438E79A}, RM: {EFC548C0-EBCB-11E6-AA2C-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[2898]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:36.854
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\DRIVERS was reorganized with a starting size of 5554176 bytes and an ending size of 5517312 bytes.

Event[2899]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:36.856
  Event ID: 11
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
TxR init phase for hive \??\GLOBALROOT\Device\HarddiskVolumeShadowCopy2\WINDOWS\System32\config\DRIVERS (TM: {EFC548C3-EBCB-11E6-AA2C-240A6438E79A}, RM: {EFC548C2-EBCB-11E6-AA2C-240A6438E79A}) finished with result=0xC00000A2 (Internal code=7).

Event[2900]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:38.320
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{924F051C-4102-4B2C-9D4A-9ED24359D29A} was reorganized with a starting size of 21848064 bytes and an ending size of 20348928 bytes.

Event[2901]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:38.500
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{1690509F-9662-4085-9C46-1F4A6F73E0A4} was cleared updating 73 keys and creating 7 modified pages.

Event[2902]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:38.694
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{4B7321F4-EBCA-4B8B-98F2-2484B4B08B1A} was cleared updating 100 keys and creating 5 modified pages.

Event[2903]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:40.463
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{3FF5AD06-4C09-42C9-BF1D-B8FE6C018BB1} was reorganized with a starting size of 52416512 bytes and an ending size of 52445184 bytes.

Event[2904]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:40.958
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{D9835DAE-5612-4AFA-8E71-D2A5980C3CD5} was reorganized with a starting size of 12537856 bytes and an ending size of 11837440 bytes.

Event[2905]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:41.357
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{D6AF4D54-1D7C-412B-ACB6-2B932A8A7251} was cleared updating 4018 keys and creating 282 modified pages.

Event[2906]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:50:44.121
  Event ID: 15
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Hive \??\Volume{5f99e753-b954-11e3-8016-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{723827DC-A69D-4652-A2A2-6B5846509A5D} was reorganized with a starting size of 98226176 bytes and an ending size of 95805440 bytes.

Event[2907]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:59:44.006
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\c:\users\defaultapppool\ntuser.dat was cleared updating 609 keys and creating 37 modified pages.

Event[2908]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T12:59:44.010
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\c:\users\defaultapppool\AppData\Local\Microsoft\Windows\usrclass.dat was cleared updating 6 keys and creating 1 modified pages.

Event[2909]:
  Log Name: System
  Source: User32
  Date: 2017-02-05T21:54:10.307
  Event ID: 1074
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The process C:\Windows\System32\RuntimeBroker.exe (COOLBLOSSOM13) has initiated the power off of computer COOLBLOSSOM13 on behalf of user CoolBlossom13\Roberto for the following reason: Other (Unplanned)
 Reason Code: 0x0
 Shutdown Type: power off
 Comment: 

Event[2910]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-05T21:54:14.082
  Event ID: 6006
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was stopped.

Event[2911]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-05T21:54:13.548
  Event ID: 7002
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logoff Notification for Customer Experience Improvement Program

Event[2912]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-05T21:54:14.097
  Event ID: 51047
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is stopped. ShutDown Flag value is 1

Event[2913]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-05T21:54:14.097
  Event ID: 50037
  Task: Service State Event
  Level: Information
  Opcode: ServiceStop
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is stopped. ShutDown Flag value is 1

Event[2914]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-06T10:13:08.466
  Event ID: 6009
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Microsoft (R) Windows (R) 10.00. 14393  Multiprocessor Free.

Event[2915]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-06T10:13:08.466
  Event ID: 6005
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Event log service was started.

Event[2916]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-06T10:13:08.466
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 12 seconds.

Event[2917]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T21:54:14.202
  Event ID: 10002
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has stopped.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2918]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-05T21:54:14.257
  Event ID: 4001
  Task: N/A
  Level: Information
  Opcode: Stop
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully stopped.


Event[2919]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T21:54:19.047
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2920]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-05T21:54:19.047
  Event ID: 109
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The kernel power manager has initiated a shutdown transition.

Shutdown Reason: Kernel API

Event[2921]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-05T21:54:19.242
  Event ID: 13
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The operating system is shutting down at system time ?2017?-?02?-?06T03:54:19.242991200Z.

Event[2922]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-06T10:12:55.657
  Event ID: 12
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The operating system started at system time ?2017?-?02?-?06T16:12:55.495071800Z.

Event[2923]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 153
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The Virtualization Based Security (policies: 0) is disabled with status STATUS_SUCCESS.

Event[2924]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 20
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The last shutdown's success status was true. The last boot's success status was true.

Event[2925]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 27
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot type was 0x0.

Event[2926]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 25
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The boot menu policy was 0x1.

Event[2927]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
There are 0x1 boot options on this system.

Event[2928]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.657
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The bootmgr spent 0 ms waiting for user input.

Event[2929]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Boot
  Date: 2017-02-06T10:12:55.658
  Event ID: 30
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The firmware reported boot metrics.

Event[2930]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:12:56.345
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileInfo' (10.0, ?2016?-?07?-?15T20:26:05.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2931]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:12:56.345
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'Wof' (10.0, ?2016?-?08?-?05T21:45:24.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2932]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:12:56.345
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'WdFilter' (10.0, ?2016?-?07?-?15T20:25:21.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2933]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-06T10:13:05.016
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume C: (\Device\HarddiskVolume4) is healthy.  No action is needed.

Event[2934]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:05.071
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'FileCrypt' (10.0, ?2016?-?07?-?15T20:22:39.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2935]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:05.122
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'npsvctrig' (10.0, ?2016?-?07?-?15T20:28:33.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2936]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Power
  Date: 2017-02-06T10:13:05.136
  Event ID: 172
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Connectivity state in standby: Disconnected, Reason: NIC compliance

Event[2937]:
  Log Name: System
  Source: Microsoft-Windows-DriverFrameworks-UserMode
  Date: 2017-02-06T10:13:05.328
  Event ID: 10114
  Task: Startup of the UMDF reflector
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WUDFPf (part of UMDF) did not load yet. After it does, Windows will start the device again.

Event[2938]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-PnP
  Date: 2017-02-06T10:13:05.328
  Event ID: 219
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The driver \Driver\WUDFRd failed to load for the device ACPI\PNP0A0A\2&daba3ff&2.

Event[2939]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-06T10:13:05.487
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume E: (\Device\HarddiskVolume1) is healthy.  No action is needed.

Event[2940]:
  Log Name: System
  Source: MEIx64
  Date: 2017-02-06T10:13:05.505
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Management Engine Interface driver has started successfully.

Event[2941]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-06T10:13:05.702
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 0 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2942]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-06T10:13:05.705
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 1 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2943]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-06T10:13:05.705
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 2 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2944]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-Processor-Power
  Date: 2017-02-06T10:13:05.705
  Event ID: 55
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Processor 3 in group 0 exposes the following power management capabilities:

Idle state type: ACPI Idle (C) States (2 state(s))

Performance state type: ACPI Performance (P) / Throttle (T) States
Nominal Frequency (MHz): 3501
Maximum performance percentage: 100
Minimum performance percentage: 22
Minimum throttle percentage: 22

Event[2945]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-06T10:13:05.866
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume F: (\Device\HarddiskVolume2) is healthy.  No action is needed.

Event[2946]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-06T10:13:05.968
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{5f99e752-b954-11e3-8016-806e6f6e6963} (\Device\HarddiskVolume3) is healthy.  No action is needed.

Event[2947]:
  Log Name: System
  Source: Microsoft-Windows-Ntfs
  Date: 2017-02-06T10:13:05.979
  Event ID: 98
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Volume \\?\Volume{29319bba-0000-0000-0000-50c837000000} (\Device\HarddiskVolume5) is healthy.  No action is needed.

Event[2948]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:06.470
  Event ID: 18
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Windows cannot store Bluetooth authentication codes (link keys) on the local adapter. Bluetooth keyboards might not work in the system BIOS during startup.

Event[2949]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-06T10:13:07.966
  Event ID: 14
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Credential Guard (LsaIso.exe) configuration: 0x0, 0

Event[2950]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-06T10:13:08.056
  Event ID: 16962
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Remote calls to the SAM database are being restricted using the default security descriptor: O:SYG:SYD:(A;;RC;;;BA).
For more information please see http://go.microsoft.com/fwlink/?LinkId=787651.

Event[2951]:
  Log Name: System
  Source: Microsoft-Windows-Directory-Services-SAM
  Date: 2017-02-06T10:13:08.061
  Event ID: 16953
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The password notification DLL C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files.  Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898.

Event[2952]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Connectivity\AllowBluetooth has value of: 2

Event[2953]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowDiscoverableMode has value of: 1

Event[2954]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\AllowAdvertising has value of: 1

Event[2955]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 34
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
A Bluetooth policy has changed.  Policy Bluetooth\ServicesAllowedList has value of: *

Event[2956]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 37
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted discoverability due to policy Bluetooth\AllowDiscoverableMode.

Event[2957]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 36
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio has accepted advertising due to policy Bluetooth\AllowAdvertising.

Event[2958]:
  Log Name: System
  Source: BTHUSB
  Date: 2017-02-06T10:13:08.388
  Event ID: 35
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Bluetooth radio enablement has been accepted due to policy Connectivity\AllowBluetooth.

Event[2959]:
  Log Name: System
  Source: Microsoft-Windows-WAS
  Date: 2017-02-06T10:13:09.079
  Event ID: 5211
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem'

Event[2960]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:08.409
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcifs' (10.0, ?2016?-?09?-?15T10:42:03.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2961]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:08.435
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'luafv' (10.0, ?2016?-?07?-?15T20:21:48.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2962]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:08.437
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'storqosflt' (10.0, ?2016?-?07?-?15T20:26:43.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2963]:
  Log Name: System
  Source: Microsoft-Windows-FilterManager
  Date: 2017-02-06T10:13:08.439
  Event ID: 6
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
File System Filter 'wcnfs' (10.0, ?2016?-?07?-?15T20:28:27.000000000Z) has successfully loaded and registered with Filter Manager.

Event[2964]:
  Log Name: System
  Source: Microsoft-Windows-Dhcp-Client
  Date: 2017-02-06T10:13:08.493
  Event ID: 50036
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv4 client service is started

Event[2965]:
  Log Name: System
  Source: Microsoft-Windows-DHCPv6-Client
  Date: 2017-02-06T10:13:08.505
  Event ID: 51046
  Task: Service State Event
  Level: Information
  Opcode: ServiceStart
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
DHCPv6 client service is started

Event[2966]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:13:08.810
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2967]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:13:08.841
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID 
{22279AF5-03AE-4CAF-989D-2530918B2F1C}
 and APPID 
{0773CCD6-59A2-4D26-B235-19247767E645}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2968]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:13:08.904
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The NetTcpActivator service depends on the NetTcpPortSharing service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2969]:
  Log Name: System
  Source: Microsoft-Windows-Time-Service
  Date: 2017-02-06T10:13:09.031
  Event ID: 158
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.

Event[2970]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-06T10:13:09.069
  Event ID: 4000
  Task: N/A
  Level: Information
  Opcode: Start
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN AutoConfig service has successfully started.


Event[2971]:
  Log Name: System
  Source: Microsoft-Windows-WLAN-AutoConfig
  Date: 2017-02-06T10:13:09.212
  Event ID: 10001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
WLAN Extensibility Module has successfully started.

Module Path: C:\WINDOWS\System32\bcmihvsrv64.dll


Event[2972]:
  Log Name: System
  Source: e1dexpress
  Date: 2017-02-06T10:13:09.213
  Event ID: 32
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Intel(R) Ethernet Connection I217-V
 Network link has been established at 1Gbps full duplex.


Event[2973]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-06T10:13:09.861
  Event ID: 14204
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' started.

Event[2974]:
  Log Name: System
  Source: Microsoft-Windows-WMPNSS-Service
  Date: 2017-02-06T10:13:09.873
  Event ID: 14205
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Service 'WMPNetworkSvc' stopped.

Event[2975]:
  Log Name: System
  Source: Microsoft-Windows-Winlogon
  Date: 2017-02-06T10:13:09.503
  Event ID: 7001
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
User Logon Notification for Customer Experience Improvement Program

Event[2976]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:13:09.870
  Event ID: 7001
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The upnphost service depends on the SSDPSRV service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Event[2977]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:13:09.871
  Event ID: 10005
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-20
  User Name: NT AUTHORITY\NETWORK SERVICE
  Computer: CoolBlossom13
  Description: 
DCOM got error "1068" attempting to start the service upnphost with arguments "Unavailable" in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}

Event[2978]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:13:09.873
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The WMPNetworkSvc service terminated with the following error: 
An attempt was made to reference a token that does not exist.

Event[2979]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:13:09.919
  Event ID: 7026
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The following boot-start or system-start driver(s) did not load: 
dam

Event[2980]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:13:10.184
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2981]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:13:10.186
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-19
  User Name: NT AUTHORITY\LOCAL SERVICE
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2982]:
  Log Name: System
  Source: Microsoft-Windows-Wininit
  Date: 2017-02-06T10:13:18.005
  Event ID: 11
  Task: N/A
  Level: Warning
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Custom dynamic link libraries are being loaded for every application. The system administrator should review the list of libraries to ensure they are related to trusted applications. Please visit http://support.microsoft.com/kb/197571 for more information.

Event[2983]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:15:10.040
  Event ID: 7023
  Task: N/A
  Level: Error
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The Connected Devices Platform Service service terminated with the following error: 
Unspecified error

Event[2984]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:15:22.118
  Event ID: 10010
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-21-3212359789-2164199213-3318592535-1000
  User Name: CoolBlossom13\Roberto
  Computer: CoolBlossom13
  Description: 
The server {37998346-3765-45B1-8C66-AA88CA6B20B8} did not register with DCOM within the required timeout.

Event[2985]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:17:12.032
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

Event[2986]:
  Log Name: System
  Source: Microsoft-Windows-DistributedCOM
  Date: 2017-02-06T10:17:59.834
  Event ID: 10016
  Task: N/A
  Level: Error
  Opcode: Info
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Event[2987]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:18:43.329
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2988]:
  Log Name: System
  Source: Microsoft-Windows-Kernel-General
  Date: 2017-02-06T10:19:06.204
  Event ID: 16
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: N/A
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The access history in hive \??\C:\ProgramData\Microsoft\Windows\AppRepository\Packages\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages.

Event[2989]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:19:11.587
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Skype Preview

Event[2990]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:19:11.587
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Skype Preview

Event[2991]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T10:21:09.685
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from demand start to auto start.

Event[2992]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:21:42.303
  Event ID: 44
  Task: Windows Update Agent
  Level: Information
  Opcode: Download
  Keyword: Download,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Windows Update started downloading an update.

Event[2993]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:21:47.238
  Event ID: 43
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Started
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2163.0)

Event[2994]:
  Log Name: System
  Source: Microsoft-Windows-WindowsUpdateClient
  Date: 2017-02-06T10:22:16.961
  Event ID: 19
  Task: Windows Update Agent
  Level: Information
  Opcode: Installation
  Keyword: Installation,Success
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.235.2163.0)

Event[2995]:
  Log Name: System
  Source: Lfsvc
  Date: 2017-02-06T10:28:10.886
  Event ID: 2
  Task: N/A
  Level: Information
  Opcode: Info
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
Geolocation positioning has been disabled by the user.

Event[2996]:
  Log Name: System
  Source: EventLog
  Date: 2017-02-06T12:00:00.466
  Event ID: 6013
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: N/A
  User Name: N/A
  Computer: CoolBlossom13
  Description: 
The system uptime is 6424 seconds.

Event[2997]:
  Log Name: System
  Source: Service Control Manager
  Date: 2017-02-06T14:29:30.835
  Event ID: 7040
  Task: N/A
  Level: Information
  Opcode: N/A
  Keyword: Classic
  User: S-1-5-18
  User Name: NT AUTHORITY\SYSTEM
  Computer: CoolBlossom13
  Description: 
The start type of the Background Intelligent Transfer Service service was changed from auto start to demand start.

