Event ID 10016 - DCOM Error | Source - Microsoft-Windows-DistributedCOM | Level: Error

Hi there... I am getting the above mentioned error with the
Description: dows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.
Full message is -
Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          5/15/2012 1:18:44 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          NT AUTHORITY\IUSR
Computer:      Server.domain.com
Description:
The description for Event ID 10016 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on
the local computer.
If the event originated on another computer, the display information had to be saved with the event.
The following information was included with the event:
application-specific
Local
Activation
{2D527A8C-A4B6-4E74-A63F-E867360D401C}
{B13EFBAE-7504-4938-9ED7-8E8B53E51221}
NT AUTHORITY
IUSR
S-1-5-17
LocalHost (Using LRPC)
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="49152">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2012-05-15T19:18:44.000000000Z" />
    <EventRecordID>43121</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>System</Channel>
    <Computer>Server.Domain.com</Computer>
    <Security UserID="S-1-5-17" />
  </System>
  <EventData>
    <Data Name="param1">application-specific</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{2D527A8C-A4B6-4E74-A63F-E867360D401C}</Data>
    <Data Name="param5">{B13EFBAE-7504-4938-9ED7-8E8B53E51221}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">IUSR</Data>
    <Data Name="param8">S-1-5-17</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
  </EventData>
</Event>
Please let me know any solutions to fix....
Steps, I did try from one of the blogs -
Open Component Services. Got oStart --> Control Panel --> Administrative Tools --> Components Services. Expand the Component Services branch then expand Computers, My Computer and DCOM Config. Right-click on "sms agent host" (my case) and click
Properties. Click on the Security tab and under “Launch and Activation Permissions” select "edit" and add user Local Service (Local lunch). Click OK, close the Component Services window.
In the Launch Permission dialog box, make sure that the Everyone group has Remote Launch and Remote Activation permissions.
In the Launch Permission dialog box, make sure that the SMS Reporting Users local group has following permissions:
Local Launch / Remote Launch / Local Activation / Remote Activation
Also added Remote Launch / Remote Activation permission for Network Service (for the SMS_Reporting_Point)
Added Admin Group to the "ConfigMgr Remote Control Users"
VT

In addition, In the security policy the ‘Local Service’ need to be configured for the following Policies
- Generate security audits
- Create global objects
- Replace a process level token
- Adjust memory quotas for a process
- Impersonate a client after authentication
- Log on as a service
- Bypass traverse checking
Hope this helps.
Regards,
Yan Li
hi,
i m having similiar error but with another APPID 
i did what u said in 1st part but i couldnt get what u mean in additional settings ? i couldnt do that. 
Error details :
Log Name:      System
Source:        Microsoft-Windows-DistributedCOM
Date:          7/2/2013 4:03:20 PM
Event ID:      10016
Task Category: None
Level:         Error
Keywords:      Classic
User:          LOCAL SERVICE
Computer:      THINK
Description:
The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{7160A13D-73DA-4CEA-95B9-37356478588A}
 and APPID 
{7160A13D-73DA-4CEA-95B9-37356478588A}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
    <EventID Qualifiers="0">10016</EventID>
    <Version>0</Version>
    <Level>2</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8080000000000000</Keywords>
    <TimeCreated SystemTime="2013-02-07T14:03:20.356793400Z" />
    <EventRecordID>1465</EventRecordID>
    <Correlation />
    <Execution ProcessID="868" ThreadID="2832" />
    <Channel>System</Channel>
    <Computer>THINK</Computer>
    <Security UserID="S-1-5-19" />
  </System>
  <EventData>
    <Data Name="param1">machine-default</Data>
    <Data Name="param2">Local</Data>
    <Data Name="param3">Activation</Data>
    <Data Name="param4">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
    <Data Name="param5">{7160A13D-73DA-4CEA-95B9-37356478588A}</Data>
    <Data Name="param6">NT AUTHORITY</Data>
    <Data Name="param7">LOCAL SERVICE</Data>
    <Data Name="param8">S-1-5-19</Data>
    <Data Name="param9">LocalHost (Using LRPC)</Data>
    <Data Name="param10">Unavailable</Data>
    <Data Name="param11">Unavailable</Data>
  </EventData>
</Event>

Similar Messages

  • Event ID: 10009-Microsoft Windows DistributedCOM

    You all ever seen this error from System Logs?
    The description for Event ID 10009 from source Microsoft-Windows-DistributedCOM cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component
    on the local computer.
    If the event originated on another computer, the display information had to be saved with the event.
    The following information was included with the event:
    COMPUTERNAMEHERE

    Thanks Torsten.
    From my research it looks like SCCM is trying to locate some machines that are no longer on the network but yet DNS is reporting it.
    So I have asked DNS Guys to flush or refresh the DNS.
    We often bring these dead\redundant records back from AD via the AD discovery methods ... it is a good idea to get the AD guys to do some house-cleaning or at least set the permissions on dead objects so that the Site serve performing the discovery does not
    have read access on the object.

  • Event ID: 4, Source: Microsoft-Windows-Kernel-EventTracing, maximum file size for session "ReadyBoot" has been reached.

    Hello,
    I upgraded my machine to Win7 x64 Pro about 3 weeks ago. My HW is an Asus mobo, Intel Q9450 w/8GB RAM. The boot drives are two Raptors configured as RAID01. All the drivers are the latest available from Intel, Asus and 3rd party vendors. My WEI is 5.9, limited by the disk transfer rates, otherwise 7.1 and 7.2 on the other indexes.
    I've been receiving these errors at boot;
    Log Name:      Microsoft-Windows-Kernel-EventTracing/Admin
    Source:        Microsoft-Windows-Kernel-EventTracing
    Date:          11/10/2009 7:51:03 AM
    Event ID:      4
    Task Category: Logging
    Level:         Warning
    Keywords:      Session
    User:          SYSTEM
    Computer:      herbt-PC
    Description:
    The maximum file size for session "ReadyBoot" has been reached. As a result, events might be lost (not logged) to file "C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl". The maximum files size is currently set to 20971520 bytes.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
        <EventID>4</EventID>
        <Version>0</Version>
        <Level>3</Level>
        <Task>1</Task>
        <Opcode>10</Opcode>
        <Keywords>0x8000000000000010</Keywords>
        <TimeCreated SystemTime="2009-11-10T12:51:03.393985600Z" />
        <EventRecordID>28</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="164" />
        <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
        <Computer>herbt-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="SessionName">ReadyBoot</Data>
        <Data Name="FileName">C:\Windows\Prefetch\ReadyBoot\ReadyBoot.etl</Data>
        <Data Name="ErrorCode">3221225864</Data>
        <Data Name="LoggingMode">0</Data>
        <Data Name="MaxFileSize">20971520</Data>
      </EventData>
    </Event>
    The image for PID 4 is listed as System.
    My searches have turned up similar events listed but no solutions.
    Any help would be appreciated.
    Cheers!

    Session "Circular Kernel Context Logger" failed to start with the following error: 0xC0000035
    As suggested above I assume this is a microsoft issue?  It has been discussed here and other forums for quite some time.  I never have seen a fix?  I wish when we received errors of this nature microsoft would tell us what they were.  How is this related to superfetch?  What is superfetch?  Why would superfetch have changed?
    BY THE WAY....  Superfetch is on(started) is on automatic and logs on as local system.  So this is not the cause of my issue.  Also what is readyboot?  Does the average computer really know what these programs/services or unique microsoft words/terms are?
    System
    Provider
    [ Name]
    Microsoft-Windows-Kernel-EventTracing
    [ Guid]
    {B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}
    EventID
    2
    Version
    0
    Level
    2
    Task
    2
    Opcode
    12
    Keywords
    0x8000000000000010
    TimeCreated
    [ SystemTime]
    2010-04-11T14:35:49.829600000Z
    EventRecordID
    25
    Correlation
    Execution
    [ ProcessID]
    4
    [ ThreadID]
    48
    Channel
    Microsoft-Windows-Kernel-EventTracing/Admin
    Computer
    Daddy-PC
    Security
    [ UserID]
    S-1-5-18
    EventData
    SessionName
    Circular Kernel Context Logger
    FileName
    ErrorCode
    3221225525
    LoggingMode
    268436608
    Windows7, Windows, Win7

  • Need Help Please Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 11/10/2010 4:31:37 PM Event ID: 41 Task Category: (63)

    Log Name:      System
    Source:        Microsoft-Windows-Kernel-Power
    Date:          11/10/2010 4:31:37 PM
    Event ID:      41
    Task Category: (63)
    Level:         Critical
    Keywords:      (2)
    User:          SYSTEM
    Computer:      Felix-PC
    Description:
    The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
        <EventID>41</EventID>
        <Version>2</Version>
        <Level>1</Level>
        <Task>63</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000002</Keywords>
        <TimeCreated SystemTime="2010-10-11T06:31:37.175213500Z" />
        <EventRecordID>96455</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="8" />
        <Channel>System</Channel>
        <Computer>Felix-PC</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="BugcheckCode">244</Data>
        <Data Name="BugcheckParameter1">0x3</Data>
        <Data Name="BugcheckParameter2">0xfffffa8002d20b30</Data>
        <Data Name="BugcheckParameter3">0xfffffa8002d20e10</Data>
        <Data Name="BugcheckParameter4">0xfffff80002fcd5d0</Data>
        <Data Name="SleepInProgress">false</Data>
        <Data Name="PowerButtonTimestamp">0</Data>
      </EventData>
    </Event>

        <Data Name="BugcheckCode">244</Data>
    244 (dez) = F4 (hex)
    Bug Check 0xF4: CRITICAL_OBJECT_TERMINATION -
    This indicates that a process or thread crucial to system operation has unexpectedly exited or been terminated.
    Cause
    Several processes and threads are necessary for the operation of the system. When they are terminated for any reason, the system can no longer function.
    Please copy the dmp files from the folder C:\Windows\Minidump first to your desktop, zip all dmp into 1 zip file and upload the zip file to your Skydrive [1] and post a link here, so that I can look at the dumps with the debugger and to to see the cause of
    the crash.
    André
    [1]
    http://social.technet.microsoft.com/Forums/en-US/w7itproui/thread/4fc10639-02db-4665-993a-08d865088d65
    "A programmer is just a tool which converts caffeine into code" CLIP- Stellvertreter http://www.winvistaside.de/

  • DCOM error "1260" on Windows 2008 R2 terminal server when SAP exports data into Office 2007 (Excel or Word)

    Hi all,
    We are experiencing an issue which happens at random whenever a user tries to export data from SAP into Excel or Word.  Excel or Word is started but remain empty.  We then see the below errors in the event log.  And the problem is very random
    as sometimes all they have to do is wait 10 minutes and the next try will be successful.  Not even log off/on.  Could someone tell me what the error "1260" is saying?     thanks for your help.
    Pete
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          7/23/2013 4:07:36 PM
    Event ID:      10000
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      Servername.domain.com
    Description:
    Unable to start a DCOM Server: {00020906-0000-0000-C000-000000000046}. The error:
    "1260"
    Happened while starting this command:
    "C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE" -Embedding
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          7/23/2013 3:54:34 PM
    Event ID:      10000
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      Servername.domain.com
    Description:
    Unable to start a DCOM Server: {00024500-0000-0000-C000-000000000046}. The error:
    "1260"
    Happened while starting this command:
    "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE" /automation -Embedding

    Hi,
    Based on my research, please try the following:
    Click Start, click Run, type regedit in the Open box, and then click OK.
    Locate the following registry subkey:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    Under this subkey, add the following registry entries:
    Name
    Type
    Value data
    Logoff
    REG_SZ
    TSEventLogoff
    Logon
    REG_SZ
    TSEventLogon
    Restart the Terminal Server computer.
    Note: Serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry
    before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, please refer to
    How to back up and restore the registry in Windows.
    Hope this helps.
    Best Regards
    Jeremy Wu

  • DCOM Error on T430S since System Update

    After running system update, I get the following error in the Event Log and continuous CMD Prompts opening and closing immediately.
    Event ID 10010 The server {717D1D6E-9366-44A8-A935-725C2349D888} did not register with DCOM within the required timeout.
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          07/08/2014 21:20:40
    Event ID:      10010
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          LENOVO-PC\Marissa
    Computer:      LENOVO-PC
    Description:
    The server {717D1D6E-9366-44A8-A935-725C2349D888} did not register with DCOM within the required timeout.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10010</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2014-08-07T20:20:40.326502000Z" />
        <EventRecordID>159374</EventRecordID>
        <Correlation />
        <Execution ProcessID="936" ThreadID="8348" />
        <Channel>System</Channel>
        <Computer>LENOVO-PC</Computer>
        <Security UserID="S-1-5-21-698325216-479766158-2809752964-1004" />
      </System>
      <EventData>
        <Data Name="param1">{717D1D6E-9366-44A8-A935-725C2349D888}</Data>
      </EventData>
    </Event>
    OS Win 8.1 Fully updated
    Event goes away when booted into Safe Mode with Networking.
    Have tried disabling AV, but error persists
    Any help appreciated as it is getting really irritating. 

    I found prosiable solution. 
    Run untivirus or anything that scans your system, and while it runs film your screen using video recording device.  I used my phone. because scaner slowesdown the system your phone or video camera can capture the exact problem your system is trying to show. After freezing the video you will see your problem.  
    In my case there was a BlackBerry folder that system was trying to delete but wasn't able to. So I went to save mode and deleted it. and DONE. 
    It worked for me maybe it will work for you too. 
    Good luck. 

  • DCOM Error 10009

    After renaming a Windows 2008 x86 SP 2 we now constantly see this error in the system log, DCOM is trying to connect to the old hostname, any ideas on how to resolve this?
    Jim
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          30/09/2011 09:44:09
    Event ID:      10009
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      FQDN of Server
    Description:
    DCOM was unable to communicate with the computer OLD SERVERNAME using any of the configured protocols.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="49152">10009</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2011-09-30T06:44:09.000Z" />
        <EventRecordID>89576</EventRecordID>
        <Correlation />
        <Execution ProcessID="0" ThreadID="0" />
        <Channel>System</Channel>
        <Computer>FQDN of Server</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">OLD Server Name</Data>
        <Binary>3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D3838343B392F33302F3230313120363A34343A393A3436393B5374617475733D313732323B47656E636F6D703D323B4465746C6F633D313731303B466C6167733D303B506172616D733D313B7B506172616D23303A307D3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D3838343B392F33302F3230313120363A34343A393A3436393B5374617475733D313732323B47656E636F6D703D383B4465746C6F633D313434323B466C6167733D303B506172616D733D313B7B506172616D23303A454D532D4550492D524D52317D3E</Binary>
      </EventData>
    </Event>

    Hello,
    start by that: http://technet.microsoft.com/en-us/library/cc774368(WS.10).aspx
    This
    posting is provided "AS IS" with no warranties or guarantees , and confers no rights.
    Microsoft Student
    Partner 2010 / 2011
    Microsoft Certified Professional
    Microsoft Certified Systems Administrator:
    Security
    Microsoft Certified Systems Engineer:
    Security
    Microsoft Certified Technology Specialist:
    Windows Server 2008 Active Directory, Configuration
    Microsoft Certified Technology Specialist:
    Windows Server 2008 Network Infrastructure, Configuration
    Microsoft Certified Technology Specialist:
    Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft Certified Technology Specialist:
    Windows 7, Configuring
    Microsoft Certified IT Professional: Enterprise
    Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer 

  • The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.

    Last night, some of our systems installed updates released on 11/13/2014.  
    KB3021674
    KB2901983
    KB3023266
    KB3014029
    KB3022777
    KB3020388
    KB890830
    Today, all of the servers running Windows Server 2008 R2 started logging the following error in the Security log over and over:
    Log Name:      Security
    Source:        Microsoft-Windows-Eventlog
    Date:          1/15/2015 11:12:39 AM
    Event ID:      1108
    Task Category: Event processing
    Level:         Error
    Keywords:      Audit Success
    User:          N/A
    Description:
    The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.
    Servers running Windows Server 2008 that also installed the updates are not experiencing the problem.  It looks like one of the updates may have introduced this problem with Server 2008 R2.

    ...Did you for sure confirm that:
    https://technet.microsoft.com/library/security/MS15-001
    is the cause?
    I did.  I had a VM that was not experiencing the problem.  I took a snapshot and tested the patches one by one.  Installing only KB3023266 immediately caused the issue to occur (after reboot).  A similar process was used to confirm that
    installing KB2675611 resolved the problem.
    Note that I found the installation of KB2675611 is usually quick, but it took several hours hours to install on some of our systems.  We had installed this patch a few months ago on a couple of servers and it was always quick to install.  But,
    it seems like installing it on a symptomatic system can cause it to take a long time.

  • Microsoft-Windows-Kernel-EventTracing Error 2 happens twice at boot EX2013CU7

    Not sure what it is.  The server is running Server 2012 R2 and it is a VM.  It has exchange and associated necessary features, roles, and prerequisites and nothing else installed.  I have uninstalled and reinstalled Exchange 2013 CU7 3 times
    and each time this error has been present.  It happens twice at boot and seems to cause no problems.
    Log Name:      Microsoft-Windows-Kernel-EventTracing/Admin
    Source:        Microsoft-Windows-Kernel-EventTracing
    Date:          12/23/2014 10:06:53 AM
    Event ID:      2
    Task Category: Session
    Level:         Error
    Keywords:      Session
    User:          SYSTEM
    Computer:      myserver.mydomain.local
    Description:
    Session "FastDocTracingSession" failed to start with the following error: 0xC0000035
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" />
        <EventID>2</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>2</Task>
        <Opcode>12</Opcode>
        <Keywords>0x8000000000000010</Keywords>
        <TimeCreated SystemTime="2014-12-23T17:06:53.273839900Z" />
        <EventRecordID>2</EventRecordID>
        <Correlation />
        <Execution ProcessID="3640" ThreadID="10016" />
        <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel>
        <Computer>Valis.PBJFS.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="SessionName">FastDocTracingSession</Data>
        <Data Name="FileName">
        </Data>
        <Data Name="ErrorCode">3221225525</Data>
        <Data Name="LoggingMode">9</Data>
      </EventData>
    </Event>

    Hi,
    This Event can be ignored. To prevent this Event prompt, please follow steps below:
    1. Set the MetricsSelfSelectionSelected value in the registry to
    2.
    2. Restart the
    Windows Azure Telemetry Service service.
    3. Stop the
    WindowsAzure-GuestAgent-Metrics event trace session.
    More details, please refer following blog:
    Event ID 2: Session "WindowsAzure-GuestAgent-Metrics" failed to start with the following error: 0xC0000035
    http://blogs.msdn.com/b/mast/archive/2014/07/09/event-id-2-session-quot-windowsazure-guestagent-metrics-quot-failed-to-start-with-the-following-error-0xc0000035.aspx
    Thanks
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Mavis Huang
    TechNet Community Support

  • Microsoft-Windows-Folder Redirection Error 502. CSC database locked by another user

    Dear all,
    We are finalizing our Windows 7 migration where we migrated 500+ clients. In our enterprise concept we implemented RUP (Roaming User Profiles) and Redirected Folders for all
    users. The Redirected Folders have been by enabled by a single GPO which redirects all folders from
    AppData to
    Searches \\servername.domain.name\documents$\%username%.
    Problem:
    The RUP and Redirected folders solution works fine until a new user wants to logon. This new user has been migrated to RUP and Redirected on another system and
    he just wants to work on another workplace or gets a temporary pc. What happens is that redirected folders do not work. The user gets a message that the folder is not reachable and desktop is empty.
    Troubleshooting:
    Soon I found out that something was being locked. If we used a user account which had working Redirect Folders than this
    worked for that user. An event of 10 was logged in OfflineFiles area of EventViewer to reconnect the path which was configured in the GPO.
    This is example screenshot. It says "Error on Open Folder. \\server.domain.name\documents$\%username%\Desktop refers to a location that is unavailable. It could be on a hard disk
    on this computer, or a on a network. Check to make sure that the disk is properly inserted, or that you are connected to the Internet or your network, and then try again. If it still cannot be located, the information might have been moved to a different location."
    These symptoms happen randomly and not on all workstations. The pain here is when it happens on a portable computer. For desktop we disabled the "Disable Offline Files' in "Manage
    Offline Files" control panel and then reboot. After the reboot the folders are directed
    and it works without these errors... On portable computer we can't use this work around as they need to work offline.
    If I connect to the share without the FQDN like \\servername\documents$\%username%\Desktop than this works fine and user can access all folders. When I try the FQDN path which is
    configured in the GPO to redirect user to like \\servername.domain.name\documents$\%username%\Desktop than it fails with this message. I personally think because the C:\Windows\CSC database is locked by the previous user who has been logged on this system.
    An example of the event generated in the Applications Event viewer part (I removed some username and server path):
    Log Name:      Application
    Source:        Microsoft-Windows-Folder Redirection
    Date:          1-2-2011 17:40:11
    Event ID:      502
    Task Category: None
    Level:         Error
    Keywords:     
    User:          domain\ivan
    Computer:      computer.domain.name
    Description:
    Failed to apply policy and redirect folder "Videos" to "\\servername.domain.name\documents$\ivan\Documents\My Videos".
     Redirection options=0x1001.
     The following error occurred: "Can not create folder "\\\servername.domain.name\documents$\ivan\Documents\My Videos"".
     Error details: "Access is denied.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Folder Redirection" Guid="{7D7B0C39-93F6-4100-BD96-4DDA859652C5}" />
        <EventID>502</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2011-02-01T16:40:11.486983400Z" />
        <EventRecordID>2754</EventRecordID>
        <Correlation ActivityID="{3211E6FB-2801-456D-BE6E-66AAE150A4DC}" />
        <Execution ProcessID="968" ThreadID="5856" />
        <Channel>Application</Channel>
        <Computer>computer.domain.name</Computer>
        <Security UserID="S-1-5-21-3705223304-2632712944-1292073641-26755" />
      </System>
      <EventData Name="EVENT_FDEPLOY_FailedToApplyPolicy">
        <Data Name="FromFolder">Videos</Data>
        <Data Name="ToFolder">\\servername.domain.name\documents$\ivan\Documents\My Videos</Data>
        <Data Name="Options">0x1001</Data>
        <Data Name="Error">Can not create folder "\\servername.domain.name\documents$\ivan\Documents\My Videos"</Data>
        <Data Name="ErrorDetails">Access is denied.
    </Data>
      </EventData>
    </Event> 
    Something like this I see in the Application Eventviewer:
    Environment:
    Windows 7 Enterprise client with patches until 1-Nov-2010
    Windows Server 2008 R2 for the Documents$ share
    Windows Server 2003 R2 as the domain controller
    I have tried all different option even to rebuild the CSC database but this also was not helping. I hope we are not dealing with a bug.
    Any help is much appreciated.
    Best regards, Ivan Versluis http://www.networknet.nl

    Ivan and SteveDIG - Thanks for taking the time to post detailed information about what you have found.  I have found the same things over the past few months and have been working with Microsoft to resolve this.  Like Ivan, I have been told by
    MS that this is a design problem in Windows 7, but they did admit it is a bug and did not charge me for the case.  That was the good news.  The bad news was that the problem is so 'deep' in Windows 7 that it will not be fixed until Windows 8 and
    the CSC engineering team in Redmond has rejected several requests to fix this issue in Windows 7 from several customers.  I personally feel we should have hauled our TAM in over this, but that wasn't my call so we haven't attempted to get an attitude
    change from MS.
    <RANT> I find this completely outrageous.  Windows is supposed to be a multi-user operating system suitable for deployment to mobile workforces spread around the world and often using slow VPN links.  Offline folders, folder redirection,
    slow link detection, etc. are all great on paper and as I did the design work for the W7 solution I've just built I sold these advantages heavily.  I now have serious egg on my face and am not happy.  Like others here I missed this in testing as
    multiple users are a fringe for us, but still important, I unfortunately didn't think to specifically test for multiple users, though I tested the features thoroughly and was happy with the results when used on single user machines.</RANT>
    As identified above, this issue manifests when more than one user uses a machine and their Offline folders (all redirected folders are configured this way by default) are in an offline state when the first user logs off.  The second user cannot access
    this 'offline' share so folder redirection fails.  We get burnt as we have latency=0 configured for slow link detection with Offline folders so users always work offline.  This is partly because of WAN optimisers in the network that lie to Windows
    so the online/offline transition doesn't work on slow links (not MS's fault), and partly because it made sense for other reasons.
    The workaround Microsoft and I came up with for our environment was to use individual file shares for each user.  We had been using a common file share with each user folder under that file share.  Changing to an individual share for each users
    means the share is not locked by the previous user.
    Examples
    This would cause a problem if John then Emma logged on to the same machine. Folder redirection would fail for Emma:
    \\FileServer1\Users$\john
    \\FileServer1\Users$\emma
    So would this if DFS was used
    \\my.domain\users\john            (points to \\FileServer1\Users$\John)
    \\my.domain\users\emma          (points to \\FileServer1\Users$\Emma)
    This would fix the problem:
    \\FileServer1\John$
    \\FileServer1\Emma$
    Unfortunately we then figured we could move these shares behind DFS like so:
    \\my.domain\homes\john             (points to \\FileServer1\John$)
    \\my.domain\homes\emma          (points to \\FileServer1\emma$)
    This was wrong.  The problem returned.  I assume the share that is being locked is now the DFS root and not the user share.
    The operations team here is very reluctant to go with direct access to the file servers and not use DFS as that will create issues for them in the future when they need to make file server changes.  I sympathise with them but can't see an alternative
    at the moment as we are deploying W7 and can't stop.  If I'd picked this up earlier a third party product might have been the solution (MS actually suggested this when I opened my case).
    I hope the information about individual shares above is helpful to someone.  Otherwise I don't really have more to add but I needed the rant :-)
    <RANT>BTW.  Has anyone tested changing a user’s home directory path once it is cached?  Try it. Test a scenario where you move the user from one file server to another.  You will not enjoy the results.  I'll say no more
    than this as it is off topic, but it shows the lack of investment in the CSC feature in Windows.  Very disappointing</RANT>

  • Bug Check Error on Exchange 2013: Microsoft-Windows-WER-SystemErrorReporting

    This is the error which prompted the server to reboot:
    Log Name:      System
    Source:        Microsoft-Windows-WER-SystemErrorReporting
    Date:          3/1/2015 9:27:00 PM
    Event ID:      1001
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          N/A
    Computer:      exch13-02.domain.com
    Description:
    The computer has rebooted from a bugcheck.  The bugcheck was: 0x000000ef (0xffffe000f9bfc080, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 030115-27921-01.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-WER-SystemErrorReporting" Guid="{ABCE23E7-DE45-4366-8631-84FA6C525952}" EventSourceName="BugCheck" />
        <EventID Qualifiers="16384">1001</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x80000000000000</Keywords>
        <TimeCreated SystemTime="2015-03-02T05:27:00.000000000Z" />
        <EventRecordID>36389</EventRecordID>
        <Correlation />
        <Execution ProcessID="0" ThreadID="0" />
        <Channel>System</Channel>
        <Computer>exch13-02.SC.ESILICON.com</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">0x000000ef (0xffffe000f9bfc080, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000)</Data>
        <Data Name="param2">C:\Windows\MEMORY.DMP</Data>
        <Data Name="param3">030115-27921-01</Data>
      </EventData>
    </Event>

    Hi,
    It seems like a Windows Server problem, not an Exchange Server problem.
    What’s the version of your Windows Server and Exchange Server?
    Similar thread:
    https://social.technet.microsoft.com/Forums/en-US/f132d246-7114-4223-9ff7-e72f3ade0708/exchange-server-2013-restarts-frequently-after-cumulative-update-3-is-installed?forum=exchangesvradmin
    Best Regards.
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Lynn-Li
    TechNet Community Support

  • DCOM errors ID: 10010

    Hello,
    I was checking on my "event viewer" and I found tons of errors DCOM related, all of them have as the event id: 10010.
    Checking for details is not only related to one application only but several:
    The server App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa did not register with DCOM within the required timeout.
    The server AppexNews.AppXm7hnj7tzqqzrmb6spmf0x4fb91edcc71.mca did not register with DCOM within the required timeout.
    The server Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca did not register with DCOM within the required timeout.
    The server AppexSports.AppXzwt95zf827jx8vevssdmkdacbwrgjgeb.mca did not register with DCOM within the required timeout.
    ... and much, much more different apps getting the same error.
    Runing the Windows 8.1 pro x64

    Hello, none of the errors have something to do with the display of ASP pages, it's related to specific applications like:
    The server Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca did not register with DCOM within the required timeout.
    The server AppexSports.AppXzwt95zf827jx8vevssdmkdacbwrgjgeb.mca did not register with DCOM within the required timeout.
    The server AppexNews.AppXm7hnj7tzqqzrmb6spmf0x4fb91edcc71.mca did not register with DCOM within the required timeout.
    The server App.AppX54xz6wnkhmw763c2y8tb018n7d71dtx7.wwa did not register with DCOM within the required timeout.
    ... and many many others. A thing that occurs every few minutes is the explorer restarts and when I check the event log, the DCOM errors are only ones that appear at that specific time.

  • Event ID 10 with error 0x80041010

    Hello,
    getting the following event 10 as well as a handful of others differing only in the specific wmi class referenced in the query. Appears to only be logged once at boot.
    Log Name:      Application
    Source:        Microsoft-Windows-WMI
    Event ID:      10
    Description:
    Event filter with query "select * from HP_PowerSupplyEvent" could not be reactivated in namespace "//./ROOT/WMI" because of error 0x80041010. Events cannot be delivered through this filter until the problem is corrected.
    This is an HP server and I know it's related to the HP WBEM provider. I'm using the latest version of the HP WBEM provider, and have also tried the previous version. Same results. 
    From what I've found googling the 0x8001010 error indicates an 'invalid class', however using powershell I can retrieve a reference to this class without error, and they show in the list when querying that namespace, for example:
    PS C:\> gwmi -Namespace root\wmi -list | Select-String hp_
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_FanEvent
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_UIDStateChangeEvent
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_TempSensorFailureEvent
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_PowerSupplyEvent
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_ASRStateChangeEvent
    \\DFEWWW-R5CM5N\ROOT\wmi:HP_Health
    all the classes listed in output of above PS command have an event id 10 error in the application log, just like the example I put at the beginning of this post.
    aside from "check with HP", does anyone have any idea how to resolve this? recompiling the mof's?

    I have the same problem on Windows 2008 R2 server and the WMI Diagnosis Utility doesn't work.
    May the source be with you!
    Please Mark As Answer if my post solves your problem or
    Vote As Helpful if a post has been helpful for you.
    yes, same thing happened with Windows Server 2008R2 and HP WBEM monitoring agent.
    What's the solution here ?
    /* Server Support Specialist */

  • Microsoft-Windows-Security-Auditing

    Hi,
    I having issue to isolate and identify the repeat account audit fail issue on sharepoint server.
    Any help on this is appreciated.
    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          4/4/2015 3:45:59 AM
    Event ID:      4625
    Task Category: Logon
    Level:         Information
    Keywords:      Audit Failure
    User:          N/A
    Computer:      SPT01
    Description:
    An account failed to log on.
    Subject:
     Security ID:  A\admin
     Account Name:  admin
     Account Domain:  A
     Logon ID:  0x176462
    Logon Type:   8
    Account For Which Logon Failed:
     Security ID:  NULL SID
     Account Name:  admin
     Account Domain:  a
    Failure Information:
     Failure Reason:  Unknown user name or bad password.
     Status:   0xc000006d
     Sub Status:  0xc000006a
    Process Information:
     Caller Process ID: 0xed4
     Caller Process Name: C:\Windows\System32\inetsrv\w3wp.exe
    Network Information:
     Workstation Name: SPT01
     Source Network Address: -
     Source Port:  -
    Detailed Authentication Information:
     Logon Process:  Advapi 
     Authentication Package: Negotiate
     Transited Services: -
     Package Name (NTLM only): -

    Hi,
    Based on the description of the fail issue, the account failed to log on the server and the fail reason was that Unknown user name or bad password.
    From the sub state is 0xc000006a, the description of the sub state is that user name is correct but the password is wrong. I recommend you to check if the password is right.
    You can also check the machine's PHS-AERO health by using:
    NLTEST /SC_VERIFY:domain-name
    And if the result is SUCCESS, you can also try NLTEST /SC_RESET:domain-name several times to see what happens. The SC_RESET command forces the machine to select a new DC to authenticate against and you should see a random switching between your DCs.
    There is a similar case:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/ae9da10a-b4d2-4eda-ae6d-ad61b7b6ab79/audit-failure-event-id-4625?forum=winserversecurity
    The article below is about Event ID 4625, you can take a look.
    https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4625
    Best regards,
    Sara Fan
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • Seeing multiple DCOM errors generating event ID 10016 in System Event log

    Hi there. Our current SharePoint server running Windows Server 2003, Standard Edition SP1 and not on the domain is getting it's event logs filled up every 15 minutes to an hour with the following DCOM error:
    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10016
    Date:  26/11/2014
    Time:  4:31:30 AM
    User:  NT AUTHORITY\NETWORK SERVICE
    Computer: xxx-xxx
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {61738644-F196-11D0-9953-00C04FD919C1}
     to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20).  This security permission can be modified using the Component Services administrative tool.
    For more information, see Help and Support Center at
    http://go.microsoft.com/fwlink/events.asp
    I have attempted the following fix to add the local admin account to the security permissions under the following service: 61738644-F196-11D0-9953-00C04FD919C1 which was what Microsoft recommended from looking at a few random google results which had no
    effect and caused the same error to continue to happen.
    We run Windows SharePoint Services WSS 3.0 on this server which is our primary intranet server.
    Has this happened to anyone else and what would you suggest we do to fix it?

    Hi Steven,
    The results of trying this generated the same DCOM error again at the early hours of this morning as it's always done.
    The exact error generated from the server is listed below:
    Event Type: Error
    Event Source: DCOM
    Event Category: None
    Event ID: 10016
    Date:  3/12/2014
    Time:  4:31:30 AM
    User:  NT AUTHORITY\NETWORK SERVICE
    Computer: HAL-SPS
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
    {61738644-F196-11D0-9953-00C04FD919C1}
     to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20).  This security permission can be modified using the Component Services administrative tool.
    For more information, see Help and Support Center at
    http://go.microsoft.com/fwlink/events.asp.
    Given this machine isn't on the domain and we have to log into it as local administrator, the local administrator account has been granted local launch and local activation permissions under IIS WAMREG admin on the server.
    Was this the correct account, or should I have granted permissions to another account?
    SB.

Maybe you are looking for

  • How to view to a webpage in normal view?

    Hi, I am using Flash CS4 AS3.. When I open my browser "Internet Explorer 7" it opens normal. But When I open a link using the following Flash code it opens half in length and half in width. I need to click on "Maximise" button to view in full. How to

  • How to go back to card view when an app is in full screen mode without using launcher button

    Is there a way to go back to card view when you are in full screen mode besides pressing he launcher button? This will wear that button out quick! Post relates to: HP TouchPad (WiFi) This question was solved. View Solution.

  • Make correction on Standard Hierarchy in Profit Center.

    1. Assigned a wrong std Hierarchy to Profit Center and need to make correction toward STD Hierarchy? 2. In create Profit Center Accting and Cost Center Accting, how would I toggle from one Controlling Area to another? 3. how would I delete a wrong Pr

  • In FM mode it shuts off after 60 sec.

    Brand new, fully charged battery;.... in FM radio mode, ipod SHUTS ITSELF OFF after 60 sec. of play, FROM THE LAST TIME I TOUCH THE SCREEN. I made no default settings changes.Does the same thing repeatedly. I opened the pkg, charged ipod 4 hrs (USB2)

  • Updating content of index.html file of J2EE Engine

    Hi, I would like to update the content of index.html file, which is located under D:\usr\sap\NSP\JC01\j2ee\cluster\server0\apps\sap.com\com.sap.engine.docs.examples\servlet_jsp\_default\root\index.html. I have requirement to change the html file cont