Over 1 million tech questions and answers.

Quickly clearing the 4 main event logs

Q: Quickly clearing the 4 main event logs

If you have a lot of entries in the event logs, depending on your system, it can take a bit to open the logs.  Here is a way to clear all the 4 main event logs quickly.
Open a text editor (e.g. notepad), and copy the following into it.
 

@cls
@echo on
wevtutil.exe cl Application
wevtutil.exe cl Security
wevtutil.exe cl Setup
wevtutil.exe cl System
@echo off
pause
Save it as "clear_logs.bat" (no quotes).  Now, just double click on the file, and all 4 main logs will be cleared.  It will not work on Windows XP.
 
This will work on Windows 8.1 for sure.  It should work on Windows 8, 7, maybe Vista.
Have a great day!

 

Read other answers
RELEVANCY SCORE 200
Preferred Solution: Quickly clearing the 4 main event logs

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

RELEVANCY SCORE 83.2

Is it possible to prevent JRT from clearing the event logs?
 
What is the reason behind this feature?  Event Logs are often crucial for diagnosing Windows issues.  I'm not aware of any reason that the event logs should be cleared to help with junkware removal.  Please help me understand the reason for this feature, and if possible, provide away to disable it.
 
Thanks!

A:Is it possible to prevent JRT from clearing Event Logs?

JRT's disclaimer clearly states: "This software is provided "as is" without warranty of any kind. You may use this software at your own risk."However, you can ask a question (leave a comment/suggestion) on Thisisu's JRT Blog.

Read other 12 answers
RELEVANCY SCORE 83.2

How can you clear the event logs without an event being created stating that the logs were cleared in Powershell? The "clear-eventlog" command does clear the events, however it leaves behind an event that states that the logs were cleared.
Anyway to get around this and totally clear the logs?
Thanks,

Read other answers
RELEVANCY SCORE 81.2

The is another attempt at getting this answered.
Previous replies noted that the Administrative Events under the Custom view was just a compilation of all the other logs.
I do not belive this is entirely correct as all the events in this log concern the operating system and do NOT appear in the other logs such as Application, Security, etc.
Below is an example of what is showing up on my system after all the individual logs shown under Event Viewer are cleared:




Level


Date and Time


Source


Event ID


Task Category




Warning



8/27/2015 13:59


Microsoft-Windows-DNS-Client



1014


None




Error



8/27/2015 12:56


Microsoft-Windows-Kernel-EventTracing



2


Session




Error



8/27/2015 12:56


Microsoft-Windows-Dhcp-Client



1001


Address Configuration State Event




Error



8/27/2015 12:54


Microsoft-Windows-PrintService



315


Sharing a printer




Error



8/24/2015 9:15


Microsoft-Windows-Dhcp-Client



1001


Address Configuration State Event




Error



8/24/2015 9:13


Microsoft-Windows-PrintService



315


Sharing a printer




Error



8/20/2015 3:19


Microsoft-Windows-Dhcp-Client



1001


Address Configuration State Event




Error



8/20/2015 3:17


Microsoft-Windows-PrintService



315


Sharing a printer




Error



8/17/2015 10:24


Microsoft-Windows-... Read more

Read other answers
RELEVANCY SCORE 63.6

New to the site and I hope this is in the right forum.

I am using Windows 7 Pro 64 and my main account logs in then automatically logs off. I can successfully log in using Safe Mode to this account. I created another account called test and I can access this account in both Safe and Normal modes.

I ran Malware Bytes and Avast Anti-Virus and they found nothing.

What can I do fix this issue or transfer my Outlook, programs and such to the test user account and rename it?

A:Windows 7 Main Account Logs On then Automatically Logs Off

I followed the instructions per the link and it appeared to copy everything over successfully.
Fix a corrupted user profile

The original account is still not able to logon and is on the computer. Is there anything else I should be looking at?

Read other 1 answers
RELEVANCY SCORE 61.2

What's the reason why you need to flash the bios? And what's the reason why you need to clear the cmos?
Sent from my iPhone using Tapatalk
 

A:Main Reason for flashing bios and clearing CMOS

Read other 10 answers
RELEVANCY SCORE 60

I was running 3DMark06 and got a BSOD code 124. After that every time I boot Event Viewer logs Error Codes ID 3012 and 3011. Attached are screenshots of both.

I googled this and found two different threads where someone suggested to rebuild the performance counters. Both responses were basically the same, below is one. Neither of the OP's came back and said if this worked for them.
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Re: LoadPerf 3011, 3012
Hi-
I had the same problem with LoadPerf and here is what I found out:
All performance counter names and explain text are maintained in string tables managed by the performance counter subsystem (Perflib).

The current contents of the performance counter string tables are corrupted and cannot be displayed. To correct the problem, rebuild the string tables.

User Action
To rebuild the string tables, on the computer that displayed the message, at the command prompt, type Lodctr /r
The contents of the string tables are automatically rebuilt.

I hope this helps
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Since this was from 2008 (XP?) and the other response was for Vista I wanted to see if the guru's at SevenForums thought that this was okay before I did this.

Here are the screenshoots of my two errors.

A:After BSOD Event Viewer Logs Event ID 3012 and 3011 every time I boot

Rebuilding the string tables as outlined in my first post fixed the problem.

Read other 1 answers
RELEVANCY SCORE 59.6

After too many unexplained problems, I decided to reinstall Windows 8.1 Pro x64, and migrate off of SBS 2011 Standard. In addition to the primary workstation that can't read any event logs, I built five Server 2012 R2 servers (Hyper-V host, Active Directory
VM, Exchange 2013 VM, SQL Server 2014 VM, and WSUS VM).

I was diagnosing why my workstation's Outlook cannot reach the local Exchange Server.   I tried to look at the event logs, and found the
Event Viewer cannot open the event log or custom view.  Verify that Event Log service is running (it is) or the query is too long (whatever that indicates).  The request is not supported (50)
Looking at the directory of the event logs folder.  It appears that most logs are empty, which is understandable since it's a rebuilt installation.  I found a small number of Applications and Services Logs and it appears nothing was logged since
six days ago on 4/4/2016.   On support forums, I found many have this exact problem on Win 7, Win 8, and Win 10.  Of the solutions posted none of them would even execute on my Win 8.1 Pro x64 machine.  I tried clearing the event logs (WEVTUTIL
CL logfilename) and am told Failed to clear log .... The request is not supported. 
It's very difficult to diagnose why Outlook 2013 cannot reach Exchange 2013, even if Outlook is installed on the Exchange server machine (just as a test).  The web-based Outlook owa, ecp, ... all work fine. ... Read more

Read other answers
RELEVANCY SCORE 59.6

Every time I try to clear an IIS log file, it says "cannot access denied.... the file may be in use" Tried stopping the service and deleting, but still no joy. Any ideas?
 

A:clearing IIS logs

Read other 7 answers
RELEVANCY SCORE 58.8

Hi...
Have an issue I've been dealing with for several weeks.  I have a standalone system that certain event IDs such as 4647 and 4634 and others are not populating in the security log.  Success and failures is set in the Local Group Policy,
but they are not being logged.  Performed gpupdate after making changes, and scoured the internet for a solution.  Any ideas?  Was this an issue in the past that an MS patch corrected?  Thanks in advance for any suggestions!!

Read other answers
RELEVANCY SCORE 58.8

Hello,
 
How can you clear the diagnostic PSA Event Log?
 
 
Thanks,

A:Clearing the PSA Event log

Why do you want to clear the PBA (pre boot assesment) event log?

Read other 3 answers
RELEVANCY SCORE 58.8

is there a way to clear the logs from mcafee?

A:clearing mcafee logs

McAfee log entries are automatically deleted after 30 days.

Read other 3 answers
RELEVANCY SCORE 58.4

It has been a long, long time since I have wanted to clear the event log and that was under Windows 7. I would like to clear the log under Windows 8 but can find no way to do it. It seems like I remember using 'Clear Log' under Actions but that doesn't seem to be there in Windows 8.

Will someone please point me in the right direction?

Thank you.

A:Clearing the Event Log in Windows 8

This utility is just what you need and it works on Windows 8 too!

Event Viewer One Click Clear - Windows 7 Help Forums

Just right click and select "Run as Administrator" and all logs will be cleared!

Read other 5 answers
RELEVANCY SCORE 58

If anyone who has AVG Internet Security 8.0 has found a way to clear the firewall logs, I would love to hear about it.

It seems the clear button they had in 7.5 to clear out the firewall log is missing in 8.0... along with the tech support they had for 7.5 I have not been able to locate another setting anywhere within AVG to set it so the log will clear either.

Any assistance would be appreciated.
 

A:Solved: Clearing Firewall Logs in AVG 8.0

I finally heard back from AVG and this is how the firewall logs can be cleared in the paid version 8.0:

You can delete the log files opening the following directory:
C:\Documents and Settings\All Users\Application Data\avg8\Log
There you can find all log files created by AVG. Firewall logs start with avgfw8...
 

Read other 1 answers
RELEVANCY SCORE 58

Hi everyone, I'm hoping that this wonderful community got some help for me.

I've previously done image deployment with Windows 7 and know how to prepare an image for deployment.

I'm now trying to make an image with Windows 8.1 enterprise.

I'm making an image with with PersistAllDeviceInstalls to keep the hardware configuration.
I use the gui to run sysprep oobe with generalize option checked.

After its completed, I make an image of it and deploy to test laptop 2 with the exact same specs.

After its done, and I boot it up and finish all the preparation (like computer name etc), the system boots up to the desktop.

However, here is where I realized I'm most likely doing something wrong.

The event logs are filled with data from pre-sysprep, Symantec Endpoint Protection logs are still there.

Can someone help me out here? Isn't generalize suppose to remove logs and stuff?

It's been almost 2 years since I touched sysprep and all. Hopefully someone here can shed some light about the issue I'm facing.

All help is sincerely appreciated.

A:Sysprep generalize not clearing logs

Hi Neevar, welcome to the Eight Forums.

First this warning about Sysprep GUI (from https://technet.microsoft.com/en-us/...h825084.aspx):

   Warning
In Windows 8.1, the Sysprep user interface is deprecated. The Sysprep UI will continue to be supported in this release however it may be removed in a future release. We recommend that you update your Windows deployment workflow to use the Sysprep command line. For more information about the Sysprep Command line tool, see Sysprep Command-Line Options.

To generalize your image without an answer file use command:

Code:
%windir%\system32\sysprep\sysprep.exe /generalize /oobe /shutdown


The closing option (highlighted) can be shutdown, restart or quit.

To generalize your image with an answer file use command:

Code:
%windir%\system32\sysprep\sysprep.exe /generalize /oobe /shutdown /unattend:X:\MyAnswerFile.xml


Change the answer file path and name (highlighted) accordingly

Event logs should be cleared when the /generalize switch is used. This from Microsoft TechNet support article https://technet.microsoft.com/en-us/...v=ws.10).aspx:






Generalize:
Prepares the Windows installation to be imaged. If this option is specified, all unique system information is removed from the Windows installation. The security ID (SID) resets, any system restore points are cleared, and event logs are deleted.

The next time the computer starts, the specialize configuration pass runs. A new secu... Read more

Read other 7 answers
RELEVANCY SCORE 58

I was wondering if there was any way to clear Security, Application, and System logs on a PC remotely.... We have been infected with W32.Gaobot and it fills up the logs quickly...

Any information would be great.
Thanks!
 

Read other answers
RELEVANCY SCORE 56.4

If you like holding onto your Thunderbird RSS feeds like I do, the folders can become very large.  These steps will walk you through clearing out your RSS folders, so you have a fresh start, at least from the point of having the folders cleared out.
After you do this once or twice, it should should be fairly quick for you after that.  I usually do this maybe every 2 months, but I do have a large number of feeds, and one alone has 2000+ articles in it.  Although I didn't count then all, one time in the past, I had about 15,000 articles when I cleared it.
1.  Find location of your feeds:
1.1.  Open Thunderbird.
1.2.  In the left column, click on "Blogs & News Feeds".
1.4.  In the right column, click on "View Settings for this account".
1.5.  Make note of the location in "Local directory".
2.  Disable all internet access.
2.1.  This is needed to insure that no checks happen while you're performing these steps.
3.  Open Thunderbird.
4.  In the left column, click on "Blogs & News Feeds".
5.  Expand all folders in the left column.
6.  Select all folders in the left column.
7.  Right click in left column.
8.  Click Mark All Folders read.
9.  In the right column, click on "Manage subscriptions".
10.  Click on "Export".
11.  Navigate to desktop.
12.  Click Save.
13.  Click Close.
14.  Open Windows Explorer.
15.  Navigate to the location  in step 1.5.
16. ... Read more

Read other answers
RELEVANCY SCORE 56

Event Log Explorer
A tool to help Manage, Analyze and Report Windows Event Logs
For Windows NT/2000/XP/2003 operating systems​
This is a simple, "starter" guide to help use this tool. (Note this tool will only work on Windows NT/2000/XP/2003. It will not work with Windows Vista.) Download and run Event Log Explorer.

One time initialization

Click Tree->Show Tree
Click File->New Workspace
Click File->Save Workspace As (and save your workspace file anywhere you choose)
Example: To Filter / View / Export Recent Error and Warning Log Events

Open an Event Log
>> (e.g Typically, you only need look at the System Log (for System event records) and the Application Log (for Application related events)
Filter the events you want to see (for this example we filter to only see Non-Information events that occured in the last 7 days)
>> Click View->Filter.
>> Uncheck Information. Towards the bottom of the filter window, look for ?Display event for the last? enter 7 days. Click OK
Click File->Export Log to save a copy of the events for later viewing or sending to others
>> Check: Text file, All events, Event Description
>> Uncheck Export Event Data
>> Check Close dialog when done
Click Export and save as a txt file on your Desktop
Help Troubleshooting an Event

Double click an event to see the "Event Description" (which provides more detail about the event)
Click Event ID Database button for an web page a... Read more

A:"Event Log Explorer" tool helps manage/analyze/report on your Windows Event Logs

I use the subscription to EventID.net. It has been greatly helpful. I don't have this analyser but am a big believer in using the Event Viewer. I'll add a description I have written up which will help in determining the Events: This may be useful in addition to the Event Analyzer.

One thing I have not been able to do is keep the filters set with the software in the OS.

Find the Error(s)in the Event Viewer that correspond to the crash/freeze/error message/blue screen, etc.:

Description of the Event Viewer:




Unfortunately, many Windows XP users aren't aware of the Event Viewer, what it is, where it is, how it can help with a problem:
The Event Viewer has logs for everything that happens on the computer. There are three sets of logs: System, Applications and Security. By opening the first two to display the Events, you can look for Errors that correspond to the time of the problem- in your case, the crash.

There are three types of Events in the System and Apps logs:
1. Information (white circle w/blue i): this is just basic documentation of the normal working of the System or Apps.
2. Warnings (yellow triangle w/black exclamation mark) noting some problem at that moment. Warnings usually resolve on their own. If they do not, they become>>>
3. Errors (red circle w/white X- they document something that didn't work or isn't happening as it should. Each Errors has three parts: an ID#, a Source and a Description. By doing a right clic... Read more

Read other 1 answers
RELEVANCY SCORE 55.6

how do i get nhra main event to run on windows xp dellTech Support Guy System Info Utility version 1.0.0.2
OS Version: Microsoft Windows XP Professional, Service Pack 3, 32 bit
Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz, x86 Family 6 Model 15 Stepping 6
Processor Count: 2
RAM: 1021 Mb
Graphics Card: NVIDIA GeForce 7900 GS, 256 Mb
Hard Drives: C: Total - 233279 MB, Free - 171089 MB;
Motherboard: Dell Inc., 0WG855
Antivirus: PC Cleaner Pro, Updated: Yes, On-Demand Scanner: Disabled xps 410
 

A:nhra main event

Where did you get the game? It should run as normal.
 

Read other 1 answers
RELEVANCY SCORE 55.6

here's the logs that are requested to have in the preparation guide.--------------------------------------------------------------------------------KASPERSKY ONLINE SCANNER 7 REPORT Thursday, June 12, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, June 13, 2008 00:56:48 Records in database: 857859--------------------------------------------------------------------------------Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yesScan area - Critical Areas: C:\Documents and Settings\All Users\Start Menu\Programs\Startup C:\Documents and Settings\Loren\Start Menu\Programs\Startup C:\Program Files C:\WINDOWSScan statistics: Files scanned: 69636 Threat name: 3 Infected objects: 4 Suspicious objects: 0 Duration of the scan: 00:40:56File name / Threat name / Threats countC:\Program Files\Trend Micro\HijackThis\backups\backup-20080210-154111-106.dll Infected: not-a-virus:Downloader.Win32.PopCap.b 1C:\Program Files\VirtualDJ\vdj.exe Infected: Backdoor.Win32.Bifrose.rtv 1C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b 1C:\WINDOWS\TEMP\ZUM376.tmp\upgrade.exe Infected: not-a-virus:AdWare.Win32.OneStep.c 1The selected area was scanned.Dec... Read more

A:Kaspersky/extra/main Logs

Hello xxdeusxx. to BleepingComputer.comMy name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)Please give me some time to look over your computer's log(s).Please take note of the following:In the meantime, please refrain from making any changes to your computer.Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.Finally, please reply using the button in the lower left hand corner of your screen.Since it's been a while, let's get a new DSS log set Please run Deckard's System Scanner again, this time using these instructions:(In the event you lost your copy, you can download a new one from here: Deckard's System Scanner)Click on Start, click on RunCopy and paste the following in the open window and then click OK:
"%userprofile%\desktop\dss.exe" /configThis will open up DSS configurationClick on Check All.Click Scan.
DSS will now run again.Please post back both logs that open in notepad.
Main.txt and Extra.txtSee you soon,Billy3

Read other 18 answers
RELEVANCY SCORE 51.6

Hi
Attached is two event log files, one is the system events "EVENT LOG.csv, the other is application events "APPLICATION LOG.csv.
Can you please tell me what happend, or what could have happend to this pc on the 7 October 2008 at 7 in the morning. The time and date reset after that, or it was changed by someone and i need to find out if it was the pc or someone.
thank you
 

Read other answers
RELEVANCY SCORE 51.6

Been snooping through event logs because my pc randomly freezes.I have the asus striker II extreme moboIntel Core2 Quad Q9400 Well Im getting stupid kernel errors. I want them fixed. Running windows 7 Ultimate with all updates.Log Name: SystemSource: Microsoft-Windows-Kernel-Processor-PowerDate: 9/23/2010 10:50:48 PMEvent ID: 35Task Category: (2)Level: ErrorKeywords: User: SYSTEMComputer: Vaine-PCDescription:Performance power management features on processor 0 in group 0 are disabled due to a firmware problem. Check with the computer manufacturer for updated firmware.Event Xml:<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <System> <Provider Name="Microsoft-Windows-Kernel-Processor-Power" Guid="{0F67E49F-FE51-4E9F-B490-6F2948CC6027}" /> <EventID>35</EventID> <Version>0</Version> <Level>2</Level> <Task>2</Task> <Opcode>0</Opcode> <Keywords>0x8000000000000000</Keywords> <TimeCreated SystemTime="2010-09-24T02:50:48.657200000Z" /> <EventRecordID>38790</EventRecordID> <Correlation /> <Execution ProcessID="4" ThreadID="60" /> <Channel>System</Channel> <Computer>Vaine-PC</Computer> <Security UserID="S-1-5-18" /> </System> <EventData> ... Read more

A:Event Logs

Disable Speedstep, and see if the issues go away. If it does, then you need to update your chipset drivers or keep speedstep disabled.

Read other 13 answers
RELEVANCY SCORE 51.6

Is there any way to clear all windows 8 event logs..

A:Event logs

Event Viewer One Click Clear - Windows 7 Forums
This was for windows 7 but is still working for windows 8.I'm using it.Just run it as administrator

Read other 2 answers
RELEVANCY SCORE 51.2

Hi, I have a huge problem with my power supply and video cards. I have tried to include the event log files. I just started having trouble last week, but I can see by the logs that are in the Thousands. I have Reformatted my Hard Drive, Once already. I dont know where to start, or if I should Reformat it again. I am not the best with computers, and I am sure that I have Downloaded some Crap and I am Paying for it now. I have just tried to upload my Event Logs, but it says the file is Too Large. Any Help is Greatly Appreciated. Thx

A:Event Logs in the Thousands

Firstly welcome.
Now, a description of the fault/s and any error code that may have been displayed would be a good place to start.

Read other 3 answers
RELEVANCY SCORE 51.2

Hi guys
i dont really look into my event logs because usually, i dont have the need too.

i randomly decided to look into my event log (while doing some maintenance on my setup)
and found some strange events.

two distinct event logs which are somewhat related.

Problem 1. I can cause the following event by removing my iPod from my pc via iTunes (remove virtually not physically)

Following events have
Log name: Microsoft-Windows-WMI-Activity/Operational
Event ID: 5858
Level: Error

Event 1:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_ClassErrorLogEntry"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 2:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_ClassErrorLog"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 3:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WMIBinaryMofResource where Name = "IDE\\DiskOCZ-VE... Read more

A:Strange event logs

anyone?

these errors only occur when removing a USB device.

Read other 9 answers
RELEVANCY SCORE 51.2

Hi everyone. I was just wondering if there was any real purpose in cleaning up the event/security logs ?
The actual size they take up seems minimal and I'm pretty sure mine are set to overwrite themselves when they are full.
So I guess my question is - to clean or not to clean ? pro's/con's
Thanks.

A:Event Logs - clean up or not ?

IMHO, no.

Read other 9 answers
RELEVANCY SCORE 51.2

Hi guys
For the last 4 weeks i get the following 4 errors at boot in the event viewer never get anything else just these.Can anyone translate the squiggles for me and tell me if there is anything to be worried about or not
Thankyou

A:Event viewer logs

Look in the text document you attached cuz i've put them by Event ID (written in the text document):
Event ID: 40968
Discription:
The Security System has received an authentication request that could not be decoded. The request has failed.

Problem with your system.
----------------------------------------------------------------------------------------------
Event ID: 1060
Description:
\??\C:\Windows\SysWow64\drivers\mdvrmng.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

it's either replaced by a recently installed software or infected by a virus.
----------------------------------------------------------------------------------------------
Event ID: 7000
Description:
The Mobile IP Route Manager service failed to start due to the following error:
This driver has been blocked from loading

Again it's either a virus blocking it from running or the driver got messed up.
----------------------------------------------------------------------------------------------
Fixing:
1- Event ID: 40968
Since it has the Level: Warning then I think you better try System Restore Point, if still does the same problem, run a full system scan for viruses and if you find viruses in C:\WINDOWS, then you should Format / Reinstall Windows cuz if viruses can't be fixed they will be autmoticly quarentined and leads to lose of files for windows.

2- Event ID: 1060
Since it's in the windows Fold... Read more

Read other 1 answers
RELEVANCY SCORE 51.2

Win XP: in Event Viewer there are a bunch of event logs. Is it 'safe' to delete all these logs? of course, some of them have 'red' warnings and some 'yellow'....but my pc is working just fine now. Thanks for any advice.
 

A:Event Viewer logs

It's just a log file. If you want to clear it, it'll just clear all previous events and start from scratch. It wont cause you problems.
 

Read other 1 answers
RELEVANCY SCORE 51.2

I have events from Anonymous log ons. What are those? In the security log!

For example: NT AUTHORITY\ANONYMOUS LOGON
Successful Network Logon:
User Name:
Domain:
Logon ID: (0x0,0x10FF3)
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name:
Logon GUID: -
This is the only on in almost a month!

Thank you lots!!

A:Event Viewer logs

Probably nothing to be concerned about, those are typical entries on my system.Comments from http://www.dslreports.com/forum/remark,655...ty,1~mode=flat:"A successful user logon is always listed as an event ID 528 and then you'll see a type which can be anything from 2 to 7. If it's not 528, then it's not an actual user and it's not necessarily successful.Event ID 538 is a successful logoff and not necessarily by an actual user.Event ID 540 is a successful "network" logon as in mapping a network drive. Your computer keeps checking for Network connections or shared folders, etc... on a regular basis to make sure you are connected."LouisWhat Is Anonymous Logon?

Read other 1 answers
RELEVANCY SCORE 51.2

http://www.microsoft.com/technet/scr....mspx?mfr=true

Microsoft Corporation

You can list the contents of an event log, sort by source, group by message type and more. To get the a whole log use the following command: get-eventlog [log name] get-eventlog Application

If you wish to sort the records by source use this command: get-eventlog Application | sort Source You can also group the records by Source, it can take a while depending on the number of records, but it is handy! Just run:
get-eventlog Application | group Message

Now event logs can get quite large and hold thousands and thousands of records. You can use the -Newest ### switch to retrieve a set number of the latest events recorded And, of course, these can all be combined to get exactly what you are looking for.
get-eventlog Application -newest 100 | sort source

Read other answers
RELEVANCY SCORE 51.2

hi all,
i need to print out security logs of windows 2000 servers on a daily basis.
does anyone knows how to automate this?

Thanks
 

A:printing event logs

Why not create a batch file using the Print command
then include the batch file as a scheduled task

Print [/D:device] [[drive:][path]filename[...]]

/D:device specifies the print device
 

Read other 2 answers
RELEVANCY SCORE 51.2

Is any way to join several event logs in one?

A:Join Event logs

If you are talking about Windows Logs, actually there is a way. When you open Event Viewer, you will see a 'Custom Views' group in the left sidebar. By right clicking on it you get a menu from which you can select 'Create Custom View'. That opens a new window, where you have to check the first radio button that says "by log" (it is checked by default but make sure), and on its right side there is a dropdown menu from which you can pick logs that you want. After clicking OK and naming your custom view, you will have a list of all the events from all the logs you selected.

Read other 1 answers
RELEVANCY SCORE 50.4

Hello Support,
I'm investigating a case where a log entry has been found when exporting that event file(opened in eventviewer) to text file but its not found when searching in Event Viewer.
I've done multiple searches and its not seen in event viewer but can be seen once i export the same event into text files.
Please suggest some solutions asap.

Thanks in advance.

Read other answers
RELEVANCY SCORE 50.4

I have read that I need to be checking firewall logs every day (ZDNet suggested this), and I know where to find the info. What I do not understand is how to interpret what I see. Is there a place to post here to have someone look at it, or can someone recommend other web sites that might be able to help? I have some concerns since I am seeing a lot of dropped packets.

Same question re event viewer. I see 'warnings' and dhcp and 1,000 events, but I don't know what that means, or whether I should be concerned, or take action in some way. Again, is that info something that can be looked at here, or where do I learn more about how to interpet the data?

Any suggestions/recommendations would be greatly appreciated.

A:Event Viewer and Firewall Logs

I have read that I need to be checking firewall logs every day (ZDNet suggested this),Hi Anonix -Unless you are having problems I see no reason to do this. Your Antivirus will keep a check on any problems usually.http://www.malwarebytes.org/ - or - http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREEIf you think you have problems then run Malwarebytes or SUPERAntiSpyware programs.(Both free)If there is a serious problem please post in the Malware removal area of this forum -Thank You -

Read other 4 answers
RELEVANCY SCORE 50.4

I have been encountering slow shutdown times on my desktop recently. I looked in the event logs to try and find some clue but they were not that helpful to the less than technically minded

1: EVENT_TCPIP_TCP_CONNECT_LIMIT_REACHED
I had a lot of the above that were listed both as information and warning

2: also W32time came up several time as both info and warning

3: NetBT came up several times - with
"the name MSHOME could not be registered on the interface with IP address xxx, the machine with the ip address yyy did not allow the name to be claimed by this machine.

The only hardware I have installed recently is a Belkin wireless card (whose problems I have posted elsewhere ) This may have something to do with it but I am not sure. Briefly my setup is a wireless laptop (no problems) and a wired desktop (which has been re-configured to run on wireless)

I am running Windows XP pro with SP2 on an AMD system with 2 gigs ram

I have run several virus checks and I run spybot regularly, I have a belkin router to connect through to my blueyonder broadband.

Any advice?
 

A:XP very slow shutdown - event logs

Read other 13 answers
RELEVANCY SCORE 50.4

http://tinyurl.com/gpc3c

Event Viewer in pre-Vista platforms suffers from several limitations that make it underperform as a troubleshooting tool. These limitations include a lack of support for centralized logging, inability to query across multiple logs, limited event filtering capability, and a general lack of "software intelligence" in terms of helping you understand how different events correlate with possible problems and how they can be resolved.

Windows Vista's enhanced version of Event Viewer is a big improvement in many of these areas, and while it's still not perfect (especially in the area of software intelligence) it's still a good step forward over the previous version of the tool. Let's walk through using some of these new features so you can learn how to use their capabilities for troubleshooting purposes.
 

A:Monitoring Event Logs in Vista

Wooohoo something I have been praying for since the Windows NT days has come true!
 

Read other 1 answers
RELEVANCY SCORE 50.4

Hello,
I was told that internet explorer logs are located in Event viewer > windows logs > application. After looking through that tree, I was unable to find any IE logs. How would I filter the view to only get IE; also, what would the source of IE be? Fixing
IE is a pain.

Edit: this is for Windows 10 1709.

Read other answers
RELEVANCY SCORE 50.4

Before I post my BSOD thread, what I'd like to is see where it is in event viewer, I can't find it. It happened at 11:45 yesterday (it's 12:57AM here now) the computer was off for about an hour, but the last event it shows under system is 11:06 and it's just an information event.

A:BSOD not showing in event logs, why?

There may not be a event logged depending on the type/cause of the bsod.

Read other 1 answers
RELEVANCY SCORE 50.4

Hi,

We are reading the event log information in our application from using query in windows management service and Java script. The required event log is based on the current system time that we send through the query to fetch the details. We face a problem while fetching a event log of Windows xp and Windows-7 as the actual time the error message logs differs from the system time. Also the time difference is not same in all the machines of same configuration.

Example : Conider an error is logged in windows event log at 05.00 AM but the time logged as 02.00 AM (which can also 07.00 AM or any difference of time) in the event log. Now I was unable to decide the exact time of an error log.

We made a workaround in Windows-7 by fetching it using Record ID which is increasing for every event log but the same does not work in Windows-XP as the record id is not increasing and does not look to have a standard format.

Kindly provide us some solution to fetch the error log information of the particular time.

Thanks,
Deva Veluchamy.

Read other answers
RELEVANCY SCORE 50.4

Hello:

Anyone knows if the following steps apply to Windows XP as well?

"How to Change the Default Event Viewer Log File Location"

http://support.microsoft.com/kb/216169

Thanks

Read other answers
RELEVANCY SCORE 50.4

Hi guys ,
I'm seeking help to troubleshoot my PC at times running slowly with CPU usage reeching 100%.
I'm on win2000 SP4
P4 HT 2.8
1 GB ram
5 hdd ( 40GB ata , 80GB SATA ,160GB SATA , 200GB SATA , 500 GB SATA )
I saw at event viewer these logs
Event ID - 51 - An error was detected on device \Device\Harddisk2\DR2 during a paging operation
Event ID - 51 - An error was detected on device \Device\Harddisk3\DR3 during a paging operation.
I had run chkdsk with the /F /R commands , also defrag the disks , cheched for virus , adware , spyware , trojans , checked the connections at the motherboard , repair the windows instalation but the problem insists and drives me crazy for weeks now
Any help please ?
 

Read other answers
RELEVANCY SCORE 50.4

I'm curious if there are any windows events, either system or application, that would tell me the Time Zone the system is in. If I get event logs (*.evtx) from windows 7 system from customer, how would I find out TimeZone.
Thanks,
MDExch

Read other answers
RELEVANCY SCORE 50.4

Is it possible to examine the event logs (*.evt) of Win NT/2000 on a windows 95/98 pc? If so, how?
 

Read other answers
RELEVANCY SCORE 50.4

By mistake, I have executed a wrong command (SL /e:false to disable all event logging instead of clearing it. Got it from another website ).

Now I would like to reset all my event logs to default.
Has someone an idea, how I could apply the steps from this article:
Reset an event log to default settings: Management Services (which is for Windows Server only!)
to my Windows 10 machine?

A:I would like to reset all my event logs to default

Originally Posted by WTenNewbie


By mistake, I have executed a wrong command (SL /e:false to disable all event logging instead of clearing it. Got it from another website ).

Now I would like to reset all my event logs to default.
Has someone an idea, how I could apply the steps from this article:
Reset an event log to default settings: Management Services (which is for Windows Server only!)
to my Windows 10 machine?



WTenNewbie... what was the exact command you entered, the full command?

Read other 2 answers
RELEVANCY SCORE 50.4

Hello,
I am doing proof of concept testing and I am running into a lot of scenarios where EMET blocks an exploit attempts but does not generate a log or notification. For example CVE-2015-5119. I can compromise a vulnerable test machine no problem. When I apply
EMET to IE the exploit is stopped (application crashes) but I get no event. I have been unable to generate an EMET event for IE (flash plugin) or Java so far this way. The only way that I get an EMET notification is for when I have it protecting another application
like notepad or audioconverter. I have also tried CVE-2012-4969 and CVE-2011-3544 which is a java exploit and EMET mitigates it but not message or Event log. The vulnerable system running EMET is Windows 7 SP1 with IE 8. I have tried both EMET 5.2 and
5.5. Any thoughts?

Thanks!

Read other answers
RELEVANCY SCORE 50

Hello all,

This Windows 7 utility actually works on Windows 8 Pro (at least it does on my installation).

Event Viewer One Click Clear - Windows 7 Support Forums

Use at your own risk.

Note: There are some that frown on removing historical event logs and I say "To each their own."

Good luck.

Read other answers