本帖最后由 revolutionstorm 于 2016-11-23 12:08 编辑
windows日志——应用程序(2016年11月21日-23日)
[mw_shl_code=css,true]级别 日期和时间 来源 事件 ID 任务类别
信息 2016/11/22 2:11:41 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 2:11:42 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 2:11:42 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:42;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 2:11:42 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 2:11:42 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213623)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 2:11:43 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 18:11, 0, 1, 213623, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 2:11:44 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213623)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 2:11:44 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 2:11:44 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 18:11, 0, 1, 213623, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 2:11:44 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213623)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 2:11:48 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:48;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 2:11:49 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 18:11, 0, 1, 213623, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 2:11:50 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 18:11, 0, 1, 213623, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/22 2:11:51 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 2:11:51 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213623)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 2:11:51 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213623)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 2:12:21 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 2:12:21 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T18:11:21Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 4:27:20 MsiInstaller 1040 无 正在开始 Windows Installer 事务 C:\ProgramData\Package Cache\{3D310F56-A7CA-441F-993E-35BF9CE0B021}v1.2.76.20506\Avira.OE.Setup.Msi.msi。客户端进程 ID: 6004。
信息 2016/11/22 4:27:20 Microsoft-Windows-RestartManager 10000 无 正在启动会话 0 - 2016-11-21T20:27:20.449617000Z。
信息 2016/11/22 4:27:31 Avira Service Host 0 无 服务已成功启动。
信息 2016/11/22 4:27:36 MsiInstaller 1042 无 正在结束 Windows Installer 事务 C:\ProgramData\Package Cache\{3D310F56-A7CA-441F-993E-35BF9CE0B021}v1.2.76.20506\Avira.OE.Setup.Msi.msi。客户端进程 ID: 6004。
信息 2016/11/22 4:27:36 MsiInstaller 1033 无 Windows Installer 已安装产品。产品名称: Avira Connect。产品版本: 1.2.76.20506。产品语言: 1033。制造商: Avira Operations GmbH & Co. KG。安装成功或错误状态: 0。
信息 2016/11/22 4:27:36 MsiInstaller 11707 无 Product: Avira Connect -- Installation completed successfully.
信息 2016/11/22 4:27:36 Microsoft-Windows-RestartManager 10001 无 正在结束会话 0 已启动 2016-11-21T20:27:20.449617000Z。
信息 2016/11/22 4:29:23 ESENT 325 常规 "avguard (11240) GaviDB_0: 数据库引擎已创建新数据库(1、C:\ProgramData\Avira\Antivirus\EVENTDB\gavi3.db)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.016, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000."
信息 2016/11/22 4:29:23 ESENT 105 常规 "avguard (11240) GaviDB_0: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 4:29:23 ESENT 102 常规 avguard (11240) GaviDB_0: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 4:29:32 Avira Antivirus 4096 (1) "无法找到来自源 Avira Antivirus 的事件 ID 4096 的描述。本地计算机上未安装引发此事件的组件,或者安装已损坏。可以安装或修复本地计算机上的组件。
如果该事件产生于另一台计算机,则必须在该事件中保存显示信息。
以下是包含在事件中的信息:
0x0
"
信息 2016/11/22 4:36:54 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/22 4:42:55 MsiInstaller 1040 无 正在开始 Windows Installer 事务 C:\ProgramData\\Comodo\Installer\cis_setup_x64.msi。客户端进程 ID: 1956。
信息 2016/11/22 4:42:59 Microsoft-Windows-RestartManager 10000 无 正在启动会话 0 - 2016-11-21T20:42:59.103422900Z。
错误 2016/11/22 4:43:01 Microsoft-Windows-CAPI2 513 无 "加密服务处理系统写入程序对象中的 OnIdentity() 调用时失败。
Details:
AddLegacyDriverFiles: Unable to back up image of binary 360FsFlt mini-filter driver.
System Error:
系统找不到指定的文件。
。"
错误 2016/11/22 4:43:01 Microsoft-Windows-CAPI2 513 无 "加密服务处理系统写入程序对象中的 OnIdentity() 调用时失败。
Details:
AddLegacyDriverFiles: Unable to back up image of binary 360Safe Camera Filter Service.
System Error:
系统找不到指定的文件。
。"
错误 2016/11/22 4:43:01 Microsoft-Windows-CAPI2 513 无 "加密服务处理系统写入程序对象中的 OnIdentity() 调用时失败。
Details:
AddLegacyDriverFiles: Unable to back up image of binary 360Safe Anti Hacker Service.
System Error:
系统找不到指定的文件。
。"
错误 2016/11/22 4:43:01 Microsoft-Windows-CAPI2 513 无 "加密服务处理系统写入程序对象中的 OnIdentity() 调用时失败。
Details:
AddLegacyDriverFiles: Unable to back up image of binary BAPIDRV.
System Error:
系统找不到指定的文件。
。"
错误 2016/11/22 4:43:01 Microsoft-Windows-CAPI2 513 无 "加密服务处理系统写入程序对象中的 OnIdentity() 调用时失败。
Details:
AddWin32ServiceFiles: Unable to back up image of service 主动防御 since QueryServiceConfig API failed
System Error:
系统找不到指定的文件。
。"
信息 2016/11/22 4:43:05 System Restore 8194 无 "成功地创建还原点(进程 = C:\Windows\Installer\MSI1716.tmp -rptype 0 -descr ""Installing COMODO Firewall"" -logfile ""C:\Users\ADMINI~1\AppData\Local\Temp\COMODO Internet Security dbgout.log"" -working; 描述 = Installing COMODO Firewall)。"
信息 2016/11/22 4:43:06 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 4:43:09 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 4:43:09 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 4:43:12 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213472)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:43:12 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 4:43:12 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 4:43:12 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 4:43:13 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:13;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisEvent”,但该查询的目标类“CisEvent”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisStatusChange”,但该查询的目标类“CisStatusChange”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisNotification”,但该查询的目标类“CisNotification”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisEvent”,但该查询的目标类“CisEvent”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisFileRatingChange”,但该查询的目标类“CisFileRatingChange”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM AvAlert”,但该查询的目标类“AvAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisAlert”,但该查询的目标类“CisAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM FwAlert”,但该查询的目标类“FwAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM DfAlert”,但该查询的目标类“DfAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisNotification”,但该查询的目标类“CisNotification”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisStatusChange”,但该查询的目标类“CisStatusChange”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisFileRatingChange”,但该查询的目标类“CisFileRatingChange”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM FwAlert”,但该查询的目标类“FwAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM CisAlert”,但该查询的目标类“CisAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM AvAlert”,但该查询的目标类“AvAlert”不存在。将忽略该查询。
错误 2016/11/22 4:43:13 Microsoft-Windows-WMI 24 无 事件提供程序 CisWmi 尝试在 //./root/cis 命名空间中注册查询“SELECT * FROM DfAlert”,但该查询的目标类“DfAlert”不存在。将忽略该查询。
信息 2016/11/22 4:43:15 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 20:43, 0, 1, 213472, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 4:43:16 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213472)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 4:43:16 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 4:43:16 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 20:43, 0, 1, 213472, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 4:43:16 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213472)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:43:19 MsiInstaller 1042 无 正在结束 Windows Installer 事务 C:\ProgramData\\Comodo\Installer\cis_setup_x64.msi。客户端进程 ID: 1956。
信息 2016/11/22 4:43:19 MsiInstaller 1033 无 Windows Installer 已安装产品。产品名称: COMODO Firewall。产品版本: 8.4.0.5165。产品语言: 2052。制造商: COMODO Security Solutions Inc.。安装成功或错误状态: 0。
信息 2016/11/22 4:43:19 MsiInstaller 11707 无 产品: COMODO Firewall -- 成功地完成了安装。
信息 2016/11/22 4:43:19 Microsoft-Windows-RestartManager 10001 无 正在结束会话 0 已启动 2016-11-21T20:42:59.103422900Z。
信息 2016/11/22 4:43:46 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 4:43:46 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T20:42:46Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 4:44:12 VSS 8225 无 由于关闭了服务控制管理器中的事件,VSS 服务将关闭。
信息 2016/11/22 4:44:12 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 4:44:12 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 4:44:12 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 4:44:59 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 4:44:59 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 4:45:01 ESENT 326 常规 "avguard (1648) GaviDB_0: 数据库引擎已附加数据库(1、C:\ProgramData\Avira\Antivirus\EVENTDB\gavi3.db)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 4:45:01 ESENT 105 常规 "avguard (1648) GaviDB_0: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 4:45:01 ESENT 102 常规 avguard (1648) GaviDB_0: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 4:45:02 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 4:45:03 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 4:45:03 Avira Service Host 0 无 服务已成功启动。
信息 2016/11/22 4:45:03 ESENT 102 常规 SearchIndexer (1888) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 4:45:03 ESENT 105 常规 "SearchIndexer (1888) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.015, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 4:45:03 ESENT 326 常规 "SearchIndexer (1888) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 4:45:03 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 4:45:10 Avira Antivirus 4096 (1) "无法找到来自源 Avira Antivirus 的事件 ID 4096 的描述。本地计算机上未安装引发此事件的组件,或者安装已损坏。可以安装或修复本地计算机上的组件。
如果该事件产生于另一台计算机,则必须在该事件中保存显示信息。
以下是包含在事件中的信息:
0x0
"
信息 2016/11/22 4:45:12 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 4:45:12 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 4:45:12 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 4:45:12 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 4:45:14 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=logon;sessionid=1"
信息 2016/11/22 4:45:16 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 4:45:16 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213470)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:45:16 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 4:45:18 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:18;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 4:45:18 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:17;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
错误 2016/11/22 4:45:19 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 4:45:19 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 20:45, 0, 1, 213470, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 4:45:19 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213470)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:45:19 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 20:45, 0, 1, 213470, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 4:45:19 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213470)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:45:21 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213469)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 4:45:21 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 4:45:21 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 20:45, 0, 1, 213470, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 4:45:21 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213469)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:45:51 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 4:45:51 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T20:44:51Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 4:47:11 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 4:47:13 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 4:47:13 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213468)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 4:47:13 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 4:47:43 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 4:47:43 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T20:44:43Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 4:49:53 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 4:49:53 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
信息 2016/11/22 4:51:50 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-21T20:51:50.062687700Z。
信息 2016/11/22 4:51:54 AviraSpeedupService 0 无 服务已成功启动。
信息 2016/11/22 4:52:02 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira System Speedup 3.0.0)。
信息 2016/11/22 4:52:04 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-21T20:51:50.062687700Z。
信息 2016/11/22 4:52:04 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2.
信息 2016/11/22 4:52:07 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2.
信息 2016/11/22 4:52:07 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy2.
信息 2016/11/22 4:55:03 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/22 5:03:19 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:03:30 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 5:03:35 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 5:03:35 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy3.
信息 2016/11/22 5:05:38 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:05:49 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy4.
信息 2016/11/22 5:05:50 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy4.
信息 2016/11/22 5:05:50 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy4.
信息 2016/11/22 5:08:48 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/22 5:09:48 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:09:59 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5.
信息 2016/11/22 5:10:00 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5.
信息 2016/11/22 5:10:00 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5.
信息 2016/11/22 5:10:06 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:10:17 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy6.
信息 2016/11/22 5:10:18 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy6.
信息 2016/11/22 5:10:18 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy6.
信息 2016/11/22 5:10:33 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:10:44 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy7.
信息 2016/11/22 5:10:45 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy7.
信息 2016/11/22 5:10:45 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy7.
信息 2016/11/22 5:10:50 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:11:01 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy8.
信息 2016/11/22 5:11:02 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy8.
信息 2016/11/22 5:11:02 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy8.
信息 2016/11/22 5:11:36 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:11:46 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy9.
信息 2016/11/22 5:11:47 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy9.
信息 2016/11/22 5:11:47 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy9.
信息 2016/11/22 5:11:52 System Restore 8194 无 成功地创建还原点(进程 = C:\Windows\system32\wbem\wmiprvse.exe; 描述 = Avira 系统加速优化)。
信息 2016/11/22 5:12:03 Microsoft-Windows-System-Restore 8300 无 Scoping started for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy10.
信息 2016/11/22 5:12:04 Microsoft-Windows-System-Restore 8302 无 Scoping successfully completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy10.
信息 2016/11/22 5:12:04 Microsoft-Windows-System-Restore 8301 无 Scoping completed for shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy10.
信息 2016/11/22 5:15:02 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/22 5:16:15 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 5:16:15 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
警告 2016/11/22 5:16:15 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
5 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500:
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1648 (\Device\HarddiskVolume1\Program Files (x86)\Avira\Antivirus\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 1048 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 2040 (\Device\HarddiskVolume1\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
"
信息 2016/11/22 5:16:16 AviraSpeedupService 0 无 服务已成功关闭。
信息 2016/11/22 5:16:16 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 5:17:04 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 5:17:04 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 5:17:06 ESENT 326 常规 "avguard (1640) GaviDB_0: 数据库引擎已附加数据库(1、C:\ProgramData\Avira\Antivirus\EVENTDB\gavi3.db)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 5:17:06 ESENT 105 常规 "avguard (1640) GaviDB_0: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.015, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 5:17:06 ESENT 102 常规 avguard (1640) GaviDB_0: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 5:17:08 ESENT 326 常规 "SearchIndexer (1988) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.016, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 5:17:08 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 5:17:08 Avira Service Host 0 无 服务已成功启动。
信息 2016/11/22 5:17:08 AviraSpeedupService 0 无 服务已成功启动。
信息 2016/11/22 5:17:08 ESENT 102 常规 SearchIndexer (1988) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 5:17:08 ESENT 105 常规 "SearchIndexer (1988) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.015, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 5:17:08 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 5:17:08 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 5:17:15 Avira Antivirus 4096 (1) "无法找到来自源 Avira Antivirus 的事件 ID 4096 的描述。本地计算机上未安装引发此事件的组件,或者安装已损坏。可以安装或修复本地计算机上的组件。
如果该事件产生于另一台计算机,则必须在该事件中保存显示信息。
以下是包含在事件中的信息:
0x0
"
信息 2016/11/22 5:17:16 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 5:17:16 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 5:17:16 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 5:17:16 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 5:17:19 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=logon;sessionid=1"
信息 2016/11/22 5:17:21 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 5:17:21 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213437)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 5:17:21 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 5:17:22 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:22;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 5:17:22 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:21;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 5:17:23 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213437)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 5:17:23 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 5:17:23 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 21:17, 0, 1, 213437, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 5:17:23 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213437)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 5:17:24 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 21:17, 0, 1, 213437, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 5:17:25 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213437)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 5:17:25 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 5:17:25 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/21 21:17, 0, 1, 213437, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 5:17:25 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213437)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 5:17:32 Microsoft-Windows-Perflib 1017 无 “CmdAgent”服务的性能计数器数据集合已禁用。原因是该服务的性能计数器库产生一个或多个错误。导致该操作的错误已写入应用程序事件日志中。启用此服务的性能计数器之前,请更正这些错误。
错误 2016/11/22 5:17:32 Microsoft-Windows-Perflib 1022 无 Windows 无法在 32 位环境中打开 64 位可扩展计数器 DLL CmdAgent。请与文件供应商联系以获得 32 位版本。或者,如果你运行的 64 位原生环境,则可以通过使用 64 位版本的性能监视器来打开这个 64 位可扩展计数器 DLL。要使用此工具,请打开 Windows 文件夹,打开 Syswow32 文件夹,然后启动 Perfmon.exe。
信息 2016/11/22 5:17:55 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 5:17:55 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T21:16:55Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 5:19:16 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213436)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 5:19:16 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 5:19:16 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 5:19:16 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 5:19:46 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 5:19:46 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-22T21:16:46Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 5:21:18 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 5:21:18 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
信息 2016/11/22 5:50:47 AviraSpeedupService 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 5:50:47 Avira Service Host 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 9:26:08 Avira Service Host 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 9:26:08 AviraSpeedupService 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 9:26:08 Avira Service Host 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 9:26:08 AviraSpeedupService 0 无 该服务已成功处理 PowerEvent。
信息 2016/11/22 9:26:10 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213189)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 9:26:10 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 9:26:10 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 9:26:10 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 9:26:11 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:10;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 9:26:12 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 01:26, 0, 1, 213189, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 9:26:13 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213189)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 9:26:13 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 01:26, 0, 1, 213189, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/22 9:26:14 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 9:26:14 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213189)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 9:26:17 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:17;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 9:26:18 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 01:26, 0, 1, 213189, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 9:26:19 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213189)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 9:26:19 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213189)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 9:26:19 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 01:26, 0, 1, 213189, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/22 9:26:20 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 9:26:50 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 9:26:50 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T01:25:49Z 时重新启动成功。原因: RulesEngine。
错误 2016/11/22 10:08:25 Microsoft-Windows-Perflib 1010 无 DLL“Spooler”中“C:\Windows\System32\winspool.drv”服务的收集过程生成了错误,或返回了无效状态。计数器 DLL 返回的性能数据将不会返回到 Perf 数据块中。数据段的第一个四字节 (DWORD) 包含异常代码或状态代码。
错误 2016/11/22 10:08:25 Microsoft-Windows-Perflib 1023 无 Windows 无法加载可扩展计数器 DLL rdyboost。数据部分的前四个字节(DWORD)包含 Windows 错误代码。
信息 2016/11/22 10:39:50 AviraSpeedupService 0 无 服务已成功停止。
信息 2016/11/22 10:57:10 Avira Antivirus 4097 (1) "无法找到来自源 Avira Antivirus 的事件 ID 4097 的描述。本地计算机上未安装引发此事件的组件,或者安装已损坏。可以安装或修复本地计算机上的组件。
如果该事件产生于另一台计算机,则必须在该事件中保存显示信息。
以下是包含在事件中的信息:
0x0
"
信息 2016/11/22 10:57:12 ESENT 103 常规 "avguard (1640) GaviDB_0: 数据库引擎已停止实例(0)。
异常关闭: 0
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.015, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000, [13] 0.000, [14] 0.000, [15] 0.000."
信息 2016/11/22 10:57:25 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 10:57:25 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
警告 2016/11/22 10:57:25 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
1 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500:
Process 1048 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
"
信息 2016/11/22 10:57:25 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 10:58:17 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 10:58:17 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 10:58:23 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 10:58:23 Avira Service Host 0 无 服务已成功启动。
信息 2016/11/22 10:58:23 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 10:58:23 ESENT 102 常规 SearchIndexer (1644) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 10:58:23 ESENT 105 常规 "SearchIndexer (1644) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 10:58:23 ESENT 326 常规 "SearchIndexer (1644) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.015, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 10:58:23 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 10:58:23 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 10:58:24 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 10:58:24 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 10:58:24 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 10:58:27 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 10:58:28 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 10:58:28 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213096)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 10:58:28 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 10:58:29 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:29;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 10:58:29 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:28;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 10:58:30 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213096)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 10:58:30 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 10:58:30 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213096)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 10:58:30 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 02:58, 0, 1, 213096, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 10:58:30 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 02:58, 0, 1, 213096, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 10:58:31 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213096)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 10:58:31 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 10:58:31 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 02:58, 0, 1, 213096, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 10:58:31 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213096)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 10:59:01 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 10:59:01 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T02:58:01Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 11:00:23 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 11:00:24 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 11:00:24 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213094)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:00:24 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 11:00:37 MsiInstaller 1040 无 正在开始 Windows Installer 事务 {3D310F56-A7CA-441F-993E-35BF9CE0B021}。客户端进程 ID: 3872。
信息 2016/11/22 11:00:37 Microsoft-Windows-RestartManager 10000 无 正在启动会话 0 - 2016-11-22T03:00:37.172412900Z。
信息 2016/11/22 11:00:44 Avira Service Host 0 无 服务已成功停止。
信息 2016/11/22 11:00:46 MsiInstaller 1042 无 正在结束 Windows Installer 事务 {3D310F56-A7CA-441F-993E-35BF9CE0B021}。客户端进程 ID: 3872。
信息 2016/11/22 11:00:46 MsiInstaller 1034 无 Windows Installer 已删除产品。产品名称: Avira Connect。产品版本: 1.2.76.20506。产品语言: 1033。制造商: Avira Operations GmbH & Co. KG。删除成功或错误状态: 0。
信息 2016/11/22 11:00:46 MsiInstaller 11724 无 Product: Avira Connect -- Removal completed successfully.
信息 2016/11/22 11:00:46 Microsoft-Windows-RestartManager 10001 无 正在结束会话 0 已启动 2016-11-22T03:00:37.172412900Z。
信息 2016/11/22 11:00:54 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T02:57:54Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 11:00:54 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 11:04:21 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 11:04:21 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
信息 2016/11/22 11:06:58 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 11:06:58 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
警告 2016/11/22 11:06:58 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
1 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500:
Process 1040 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
"
信息 2016/11/22 11:06:59 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 11:07:40 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 11:07:40 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 11:07:45 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 11:07:46 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 11:07:46 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 11:07:46 ESENT 102 常规 SearchIndexer (1628) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 11:07:46 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 11:07:46 ESENT 326 常规 "SearchIndexer (1628) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 11:07:46 ESENT 105 常规 "SearchIndexer (1628) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.016, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 11:07:46 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 11:07:46 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 11:07:46 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 11:07:48 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=logon;sessionid=1"
信息 2016/11/22 11:07:49 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 11:07:49 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213087)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:07:49 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 11:07:50 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:50;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 11:07:50 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:49;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
错误 2016/11/22 11:07:51 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 11:07:51 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 03:07, 0, 1, 213087, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 11:07:51 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213087)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:07:51 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 03:07, 0, 1, 213087, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 11:07:51 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213087)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:07:53 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213087)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 11:07:53 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 11:07:53 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 03:07, 0, 1, 213087, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 11:07:53 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213087)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:08:23 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 11:08:23 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T03:07:23Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 11:09:46 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 11:09:47 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 11:09:47 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 213085)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 11:09:47 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 11:10:17 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 11:10:17 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T03:07:17Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 11:12:42 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 11:12:42 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
信息 2016/11/22 15:47:55 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 15:47:55 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
警告 2016/11/22 15:47:55 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
1 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500:
Process 364 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
"
信息 2016/11/22 15:47:55 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 15:48:46 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 15:48:46 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 15:48:52 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 15:48:52 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 15:48:52 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 15:48:52 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 15:48:52 ESENT 105 常规 "SearchIndexer (1636) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.015, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 15:48:52 ESENT 102 常规 SearchIndexer (1636) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 15:48:52 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 15:48:52 ESENT 326 常规 "SearchIndexer (1636) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 15:48:52 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 15:48:52 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 15:48:54 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 15:48:55 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 15:48:55 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212806)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 15:48:55 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 15:48:56 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:56;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 15:48:56 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:56;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 15:48:57 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 07:48, 0, 1, 212806, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 07:48, 0, 1, 212806, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212806)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 07:48, 0, 1, 212806, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212806)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 15:48:58 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212806)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 15:48:59 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 15:48:59 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212806)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 15:49:29 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 15:49:29 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T07:48:29Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 15:50:52 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 15:50:53 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 15:50:53 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212804)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 15:50:53 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 15:51:23 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 15:51:23 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T07:48:23Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 15:54:15 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 15:54:15 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
信息 2016/11/22 16:25:35 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212769)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:25:35 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 16:25:35 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 16:25:35 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 16:25:36 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:35;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 16:25:37 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:25, 0, 1, 212769, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:25:38 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212769)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 16:25:38 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 16:25:38 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:25, 0, 1, 212769, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:25:38 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212769)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:25:39 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:39;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 16:25:40 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:25, 0, 1, 212769, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:25:41 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:25, 0, 1, 212769, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/22 16:25:42 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 16:25:42 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212769)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:25:42 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212769)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:26:12 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 16:26:12 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T08:25:12Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 16:38:20 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 16:38:20 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:20;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 16:38:20 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212757)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:38:20 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 16:38:20 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 16:38:22 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:38, 0, 1, 212757, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:38:23 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212756)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 16:38:23 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 16:38:23 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:38, 0, 1, 212756, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:38:23 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212756)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:38:24 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:24;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 16:38:25 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:38, 0, 1, 212756, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:38:26 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212756)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 16:38:26 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 16:38:26 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 08:38, 0, 1, 212756, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 16:38:26 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212756)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 16:38:56 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 16:38:56 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T08:37:56Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 17:07:08 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 17:07:09 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 17:07:09 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:09;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 17:07:09 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 17:07:09 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212728)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 17:07:10 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 09:07, 0, 1, 212728, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 17:07:11 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212728)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 17:07:11 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 17:07:11 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 09:07, 0, 1, 212728, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 17:07:11 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212728)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 17:07:13 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:13;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 17:07:14 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 09:07, 0, 1, 212728, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 17:07:15 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212728)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 17:07:15 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 17:07:15 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 09:07, 0, 1, 212728, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 17:07:15 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212728)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 17:07:45 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 17:07:45 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T09:06:45Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 17:10:10 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T09:10:10.373701200Z。
信息 2016/11/22 17:10:10 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T09:10:10.373701200Z。
信息 2016/11/22 17:10:10 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T09:10:10.830238700Z。
信息 2016/11/22 17:10:10 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T09:10:10.830238700Z。
警告 2016/11/22 21:01:01 ESENT 910 性能 svchost (1300) 数据库缓存大小维护任务已用了 60 秒,但没有完成。这可能会导致服务器性能下降。 当前缓存大小为 2 个缓冲区,超过配置的缓存限制(目标百分比为 120)。 缓存大小维护已逐出 0 个缓冲区,进行了 11628 次刷新尝试,成功刷新了 0 个缓冲区。自触发维护以来,它已运行了 5864 次。
信息 2016/11/22 22:26:04 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 22:26:05 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 22:26:05 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:05;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 22:26:05 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 22:26:05 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212409)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 22:26:06 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 14:26, 0, 1, 212409, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 22:26:07 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212409)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 22:26:07 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 22:26:07 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 14:26, 0, 1, 212409, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 22:26:07 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212409)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 22:26:10 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:10;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 22:26:12 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 14:26, 0, 1, 212409, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 22:26:13 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212409)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 22:26:13 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 22:26:13 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 14:26, 0, 1, 212409, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 22:26:13 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212409)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 22:26:43 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 22:26:43 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T14:25:43Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 22:59:23 Microsoft-Windows-CAPI2 4097 无 "自动更新第三方根证书成功:: 使用者: <OU=VeriSign Commercial Software Publishers CA, O=""VeriSign, Inc."", L=Internet> Sha1 指纹: <24A40A1F573643A67F0A4B0749F6A22BF28ABB6B>。"
信息 2016/11/22 22:59:23 Microsoft-Windows-CAPI2 4100 无 自动从: <http://ctldl.windowsupdate.com/m ... 61A754976C8DD25.crt>中更新检索第三方根证书成功。
信息 2016/11/22 22:59:23 Microsoft-Windows-CAPI2 4097 无 "自动更新第三方根证书成功:: 使用者: <OU=""NO LIABILITY ACCEPTED, (c)97 VeriSign, Inc."", OU=VeriSign Time Stamping Service Root, OU=""VeriSign, Inc."", O=VeriSign Trust Network> Sha1 指纹: <18F7C1FCC3090203FD5BAA2F861A754976C8DD25>。"
信息 2016/11/22 23:00:10 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <Dot3svc> 无法处理通知事件。
信息 2016/11/22 23:00:10 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
警告 2016/11/22 23:00:10 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
29 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500:
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\MY
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Internet Explorer\Main\FeatureControl
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\Root
Process 1040 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows NT\CurrentVersion
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\Disallowed
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\DAUM\PotPlayerMini64\FileFormat
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\CA
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\EUDC
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\EUDC
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Policies\Microsoft\SystemCertificates
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Policies
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\trust
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500\Software\Microsoft\SystemCertificates\TrustedPeople
"
警告 2016/11/22 23:00:10 Microsoft-Windows-User Profiles Service 1530 无 "Windows 检测到注册表文件仍在由其他应用程序或服务使用。将立即卸载此文件。包含注册表文件的应用程序或服务以后可能无法正确运行。
详细信息 -
4 user registry handles leaked from \Registry\User\S-1-5-21-3966002941-4016560620-694418537-500_Classes:
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500_CLASSES
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500_CLASSES
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500_CLASSES
Process 1856 (\Device\HarddiskVolume1\Program Files\DAUM\PotPlayer\PotPlayerMini64.exe) has opened key \REGISTRY\USER\S-1-5-21-3966002941-4016560620-694418537-500_CLASSES\ActivatableClasses\CLSID
"
信息 2016/11/22 23:00:10 Microsoft-Windows-User Profiles Service 1532 无 "已停止用户配置文件服务。
"
信息 2016/11/22 23:00:59 Microsoft-Windows-EventSystem 4625 无 EventSystem 子系统正在取消 86400 秒持续时间内重复的事件日志项。可以通过下列注册表项下名为 SuppressDuplicateDuration 的 REG_DWORD 值控制取消超时: HKLM\Software\Microsoft\EventSystem\EventLog。
信息 2016/11/22 23:00:59 Microsoft-Windows-User Profiles Service 1531 无 "已成功启动用户配置文件服务。
"
信息 2016/11/22 23:01:05 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <AUInstallAgent> 无法处理关键通知事件。
信息 2016/11/22 23:01:05 Microsoft-Windows-Winlogon 6003 无 Winlogon 通知订户 <SessionEnv> 无法处理关键通知事件。
信息 2016/11/22 23:01:05 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <AUInstallAgent> 无法处理通知事件。
信息 2016/11/22 23:01:05 Microsoft-Windows-Winlogon 6000 无 Winlogon 通知订户 <SessionEnv> 无法处理通知事件。
信息 2016/11/22 23:01:05 ESENT 105 常规 "SearchIndexer (1648) Windows: 数据库引擎已启动新实例(0)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.015, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000."
信息 2016/11/22 23:01:05 ESENT 102 常规 SearchIndexer (1648) Windows: 数据库引擎(6.02.9200.0000)正在启动新实例(0)。
信息 2016/11/22 23:01:05 Microsoft-Windows-Search 1003 搜索服务 Windows Search 服务已启动。
信息 2016/11/22 23:01:05 ESENT 326 常规 "SearchIndexer (1648) Windows: 数据库引擎已附加数据库(1、C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb)。(时间=0 秒)
内部计时序列: [1] 0.000, [2] 0.000, [3] 0.000, [4] 0.000, [5] 0.000, [6] 0.000, [7] 0.000, [8] 0.000, [9] 0.000, [10] 0.000, [11] 0.000, [12] 0.000.
保存的缓存: 1"
信息 2016/11/22 23:01:05 Microsoft-Windows-WMI 5615 无 已成功启动 Windows Management Instrumentation 服务
信息 2016/11/22 23:01:05 Microsoft-Windows-WMI 5617 无 已成功初始化 Windows Management Instrumentation 服务子系统
信息 2016/11/22 23:01:07 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 23:01:07 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 23:01:08 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 23:01:08 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212374)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:01:09 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:09;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 23:01:09 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:08;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 23:01:10 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212374)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 23:01:10 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1"
信息 2016/11/22 23:01:10 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212374)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:01:10 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:01, 0, 1, 212374, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:01:10 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:01, 0, 1, 212374, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:01:11 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212374)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 23:01:11 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 23:01:11 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:01, 0, 1, 212374, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:01:11 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212374)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:01:41 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 23:01:41 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T15:00:41Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 23:03:05 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: <none>"
信息 2016/11/22 23:03:06 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 23:03:06 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212372)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:03:06 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 23:03:36 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 23:03:36 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T15:00:36Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/22 23:05:31 Microsoft-Windows-LoadPerf 1001 无 已成功删除 WmiApRpl (WmiApRpl)服务的性能计数器。记录数据含有系统上一个计数器和上一个“帮助”注册表项的新数值。
信息 2016/11/22 23:05:31 Microsoft-Windows-LoadPerf 1000 无 已成功加载 WmiApRpl (WmiApRpl) 服务的性能计数器。数据段中的记录数据包含分配给该服务的新索引值。
错误 2016/11/22 23:52:22 SideBySide 33 无 "“c:\program files (x86)\common files\thunder network\tp\ver1\1.1.2.265_1111\XLLuaRuntime.dll”的激活上下文生成失败。 找不到从属程序集 Microsoft.VC90.ATL,processorArchitecture=""x86"",publicKeyToken=""1fc8b3b9a1e18e3b"",type=""win32"",version=""9.0.21022.8""。 请使用 sxstrace.exe 进行详细诊断。"
信息 2016/11/22 23:58:16 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/22 23:58:17 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/22 23:58:17 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212317)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:58:17 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/22 23:58:18 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:35:17;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 23:58:19 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:58, 0, 1, 212317, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:58:20 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212317)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 23:58:20 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 23:58:20 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:58, 0, 1, 212317, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:58:20 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212317)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:58:21 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:21;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/22 23:58:22 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:58, 0, 1, 212316, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:58:24 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212316)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/22 23:58:24 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/22 23:58:24 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 15:58, 0, 1, 212316, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/22 23:58:24 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212316)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/22 23:58:54 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/22 23:58:54 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T15:57:54Z 时重新启动成功。原因: RulesEngine。
错误 2016/11/23 0:05:59 SideBySide 33 无 "“C:\Program Files (x86)\Thunder Network\Thunder\tp\XLBugReport.exe”的激活上下文生成失败。 找不到从属程序集 Microsoft.VC90.ATL,processorArchitecture=""x86"",publicKeyToken=""1fc8b3b9a1e18e3b"",type=""win32"",version=""9.0.21022.8""。 请使用 sxstrace.exe 进行详细诊断。"
信息 2016/11/23 0:54:28 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T16:54:28.906183700Z。
信息 2016/11/23 0:54:29 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T16:54:28.906183700Z。
信息 2016/11/23 0:54:29 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T16:54:29.394597400Z。
信息 2016/11/23 0:54:29 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T16:54:29.394597400Z。
信息 2016/11/23 0:57:56 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/23 1:05:37 Microsoft-Windows-Security-SPP 900 无 "软件保护服务正在启动。
参数: trigger=network;sessionid=0"
信息 2016/11/23 1:05:38 Microsoft-Windows-Security-SPP 902 无 "软件保护服务已启动。
6.2.9200.16384"
信息 2016/11/23 1:05:38 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212249)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/23 1:05:38 Microsoft-Windows-Security-SPP 1066 无 "服务对象的初始化状态。
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
"
信息 2016/11/23 1:05:39 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:38;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/23 1:05:40 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 17:05, 0, 1, 212249, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/23 1:05:41 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212249)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
错误 2016/11/23 1:05:41 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/23 1:05:41 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212249)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/23 1:05:41 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 17:05, 0, 1, 212249, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/23 1:05:41 Microsoft-Windows-Security-SPP 8230 无 "规则引擎已成功重新评估计划。
内核策略:
Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2017/04/19:02:34:41;LastConsumptionReason=0x4004f040;LastNotificationId=VolumeRenewalRequired;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=J8CK4;ProductKeyType=Volume:GVLK;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;ruleId=502ff3ba-669a-4674-bbb1-601f34a3b968;uxDifferentiator=ENVIRONMENT;volumeActivationOrder=normal"
信息 2016/11/23 1:05:42 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 17:05, 0, 1, 212249, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
信息 2016/11/23 1:05:43 Microsoft-Windows-Security-SPP 12288 无 "客户端已向密钥管理服务计算机发送了激活请求。
信息:
0xC0020017, 0x00000000, 127.0.0.2:1688, ac7eb9be-c462-4650-8977-753c03c4730c, 2016/11/22 17:05, 0, 1, 212249, a98bcd6d-5343-4603-8afe-5908e4611112, 25"
错误 2016/11/23 1:05:44 Microsoft-Windows-Security-SPP 8198 无 "许可证激活(slui.exe)失败,返回以下错误代码:
hr=0xC004F074
命令行参数:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable"
信息 2016/11/23 1:05:44 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212249)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/23 1:05:44 Microsoft-Windows-Security-SPP 1003 无 "软件保护服务已完成授权状态检查。
应用程序 ID=55c92734-d682-4d71-983e-d6ec3f16059f
授权状态=
1: 044ba67a-4c54-47ee-941a-d6f2efaa6891, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
2: 05e80e9f-93e3-4433-8b6d-bac4ae66d7bc, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
3: 0cdc4d08-6df6-4eb4-b5b4-a373c3e351e7, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
4: 24259a22-3bf0-44af-a68b-1b858bce1894, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
5: 7f71c90a-6279-4274-b398-37f7e9019dd4, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
6: 949d6b86-bfa7-4ff1-b4df-17e67bb6320d, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
7: 9e473b6d-b591-4c46-9c44-90a865f22e76, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
8: a98bcd6d-5343-4603-8afe-5908e4611112, 1, 1 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/volume/1.0 0x4004F040 212249)(?)(?)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )]
9: bbc56067-37f8-49dd-87b2-a418a9ba130a, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
10: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
11: ec67814b-30e6-4a50-bf7b-d55daf729d1e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )]
"
信息 2016/11/23 1:06:14 Microsoft-Windows-Security-SPP 903 无 "软件保护服务已经停止。
"
信息 2016/11/23 1:06:14 Microsoft-Windows-Security-SPP 16384 无 安排软件保护服务在 2016-11-23T17:05:14Z 时重新启动成功。原因: RulesEngine。
信息 2016/11/23 1:08:17 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:08:17.604956800Z。
信息 2016/11/23 1:08:17 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:08:17.604956800Z。
信息 2016/11/23 1:08:18 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:08:18.115194400Z。
信息 2016/11/23 1:08:18 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:08:18.115194400Z。
信息 2016/11/23 1:08:28 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:08:28.328898900Z。
信息 2016/11/23 1:08:28 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:08:28.328898900Z。
信息 2016/11/23 1:23:20 Wow64 Emulation Layer 1109 无 由于与 64 位版本的 Windows 不兼容,此程序或功能“\??\C:\Users\ADMINI~1\AppData\Local\Temp\romA10A.tmp.exe”无法启动或运行。请联系软件供应商询问是否有与 64 位 Windows 兼容的版本。
信息 2016/11/23 1:33:00 Wow64 Emulation Layer 1109 无 由于与 64 位版本的 Windows 不兼容,此程序或功能“\??\C:\Users\ADMINI~1\AppData\Local\Temp\rom7AB9.tmp.exe”无法启动或运行。请联系软件供应商询问是否有与 64 位 Windows 兼容的版本。
信息 2016/11/23 1:39:53 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:39:53.765636600Z。
信息 2016/11/23 1:39:53 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:39:53.765636600Z。
信息 2016/11/23 1:43:27 VSS 8224 无 由于空闲超时,VSS 服务将关闭。
信息 2016/11/23 1:56:09 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:56:09.229430500Z。
信息 2016/11/23 1:56:09 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:56:09.229430500Z。
信息 2016/11/23 1:56:24 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:56:24.622285200Z。
信息 2016/11/23 1:56:24 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:56:24.622285200Z。
信息 2016/11/23 1:57:12 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:57:12.215185400Z。
信息 2016/11/23 1:57:12 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:57:12.215185400Z。
信息 2016/11/23 1:57:14 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:57:14.796454400Z。
信息 2016/11/23 1:57:14 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:57:14.796454400Z。
信息 2016/11/23 1:57:40 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-22T17:57:40.443650300Z。
信息 2016/11/23 1:57:40 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-22T17:57:40.443650300Z。
信息 2016/11/23 2:02:03 Wow64 Emulation Layer 1109 无 由于与 64 位版本的 Windows 不兼容,此程序或功能“\??\C:\Users\ADMINI~1\AppData\Local\Temp\rom13EE.tmp.exe”无法启动或运行。请联系软件供应商询问是否有与 64 位 Windows 兼容的版本。
信息 2016/11/23 2:43:33 Wow64 Emulation Layer 1109 无 由于与 64 位版本的 Windows 不兼容,此程序或功能“\??\C:\Users\ADMINI~1\AppData\Local\Temp\romE48.tmp.exe”无法启动或运行。请联系软件供应商询问是否有与 64 位 Windows 兼容的版本。
错误 2016/11/23 10:12:45 Microsoft-Windows-Perflib 1010 无 DLL“Spooler”中“C:\Windows\System32\winspool.drv”服务的收集过程生成了错误,或返回了无效状态。计数器 DLL 返回的性能数据将不会返回到 Perf 数据块中。数据段的第一个四字节 (DWORD) 包含异常代码或状态代码。
错误 2016/11/23 10:12:45 Microsoft-Windows-Perflib 1023 无 Windows 无法加载可扩展计数器 DLL rdyboost。数据部分的前四个字节(DWORD)包含 Windows 错误代码。
信息 2016/11/23 11:37:22 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-23T03:37:22.941223400Z。
信息 2016/11/23 11:37:23 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-23T03:37:22.941223400Z。
信息 2016/11/23 11:37:23 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-23T03:37:23.511160300Z。
信息 2016/11/23 11:37:23 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-23T03:37:23.511160300Z。
信息 2016/11/23 11:37:23 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-23T03:37:23.746555100Z。
信息 2016/11/23 11:37:23 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-23T03:37:23.746555100Z。
信息 2016/11/23 11:58:50 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-23T03:58:50.919368700Z。
信息 2016/11/23 11:58:51 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-23T03:58:50.919368700Z。
信息 2016/11/23 11:58:51 Microsoft-Windows-RestartManager 10000 无 正在启动会话 1 - 2016-11-23T03:58:51.442432100Z。
信息 2016/11/23 11:58:51 Microsoft-Windows-RestartManager 10001 无 正在结束会话 1 已启动 2016-11-23T03:58:51.442432100Z。
[/mw_shl_code] |